Loading...
Loading...
The Internationalized Domain Names (IDN) blacklist in Mozilla Firefox 3.0.6 and other versions before 3.0.9; Thunderbird before 2.0.0.21; and SeaMonkey before 1.1.15 does not include box-drawing characters, which allows remote attackers to spoof URLs and conduct phishing attacks, as demonstrated by homoglyphs of the / (slash) and ? (question mark) characters in a subdomain of a .cn domain name, a different vulnerability than CVE-2005-0233. NOTE: some third parties claim that 3.0.6 is not affected, but much older versions perhaps are affected.
February 20, 2009
April 23, 2026
See which npm, PyPI, Go, and Maven packages are affected by CVE-2009-0652
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.