CVE-2009-0652

5.8
CVSS v2.0 Base Score
1.50%
LOW RiskEPSS (73rd percentile)
NVD-CWE-Other

The Internationalized Domain Names (IDN) blacklist in Mozilla Firefox 3.0.6 and other versions before 3.0.9; Thunderbird before 2.0.0.21; and SeaMonkey before 1.1.15 does not include box-drawing characters, which allows remote attackers to spoof URLs and conduct phishing attacks, as demonstrated by homoglyphs of the / (slash) and ? (question mark) characters in a subdomain of a .cn domain name, a different vulnerability than CVE-2005-0233. NOTE: some third parties claim that 3.0.6 is not affected, but much older versions perhaps are affected.

Published: 2/20/2009
Modified: 6/16/2026
Back to CVE Lookup

Vulnerability Summary

CVSS v2 Score

5.8

AV:N/AC:M/Au:N/C:N/I:P/A:P

EPSS Score (Exploitation Probability)

1.50%LOW Exploitation Risk
73rd percentile

This vulnerability has a 1.50% probability of being exploited in the next 30 days, ranking higher than 73% of all scored CVEs.

CWE Classification

NVD-CWE-Other
Advertisement