Search 211766 CVE descriptions
and 97459 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:
Category:Red Hat Local Security Checks
Title:RedHat Security Advisory RHSA-2009:0436
The remote host is missing updates announced in
advisory RHSA-2009:0436.

Mozilla Firefox is an open source Web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code as the user running Firefox.
(CVE-2009-1302, CVE-2009-1303, CVE-2009-1304, CVE-2009-1305)

Several flaws were found in the way malformed web content was processed. A
web page containing malicious content could execute arbitrary JavaScript in
the context of the site, possibly presenting misleading data to a user, or
stealing sensitive information such as login credentials. (CVE-2009-0652,
CVE-2009-1306, CVE-2009-1307, CVE-2009-1308, CVE-2009-1309, CVE-2009-1310,

A flaw was found in the way Firefox saved certain web pages to a local
file. If a user saved the inner frame of a web page containing POST data,
the POST data could be revealed to the inner frame, possibly surrendering
sensitive information such as login credentials. (CVE-2009-1311)

For technical details regarding these flaws, refer to the Mozilla security
advisories for Firefox 3.0.9. You can find a link to the Mozilla advisories
in the References section of this errata.

All Firefox users should upgrade to these updated packages, which contain
Firefox version 3.0.9, which corrects these issues. After installing the
update, Firefox must be restarted for the changes to take effect.

Please note that this update is available via
Red Hat Network. To use Red Hat Network, launch the Red
Hat Update Agent with the following command: up2date

CVSS Score:

CVSS Vector:

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2009-0652
BugTraq ID: 33837
Debian Security Information: DSA-1797 (Google Search)
Debian Security Information: DSA-1830 (Google Search)
RedHat Security Advisories: RHSA-2009:0437
SuSE Security Announcement: SUSE-SR:2009:010 (Google Search)
XForce ISS Database: mozilla-firefox-homoglyph-spoofing(48974)
Common Vulnerability Exposure (CVE) ID: CVE-2009-1302
BugTraq ID: 34656
Common Vulnerability Exposure (CVE) ID: CVE-2009-1303
Common Vulnerability Exposure (CVE) ID: CVE-2009-1304
Common Vulnerability Exposure (CVE) ID: CVE-2009-1305
Common Vulnerability Exposure (CVE) ID: CVE-2009-1306
Common Vulnerability Exposure (CVE) ID: CVE-2009-1307
Common Vulnerability Exposure (CVE) ID: CVE-2009-1308
Common Vulnerability Exposure (CVE) ID: CVE-2009-1309
Common Vulnerability Exposure (CVE) ID: CVE-2009-1310
Debian Security Information: DSA-1886 (Google Search)
Common Vulnerability Exposure (CVE) ID: CVE-2009-1311
Common Vulnerability Exposure (CVE) ID: CVE-2009-1312
Bugtraq: 20090702 Cross-Site Scripting vulnerabilities in Mozilla, Internet Explorer, Opera and Chrome (Google Search)
Bugtraq: 20090703 Re: Cross-Site Scripting vulnerabilities in Mozilla, Internet Explorer, Opera and Chrome (Google Search)
CopyrightCopyright (c) 2009 E-Soft Inc.

This is only one of 97459 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.

© 1998-2021 E-Soft Inc. All rights reserved.