Vulnerability Database

296,594

Total vulnerabilities in the database

CVE-2009-2065

Mozilla Firefox 3.0.10, and possibly other versions, detects http content in https web pages only when the top-level frame uses https, which allows man-in-the-middle attackers to execute arbitrary web script, in an https site's context, by modifying an http page to include an https iframe that references a script file on an http site, related to "HTTP-Intended-but-HTTPS-Loadable (HPIHSL) pages."

  • Published: Jun 15, 2009
  • Updated: Apr 13, 2023
  • CVE: CVE-2009-2065
  • Severity: Medium
  • Exploit:

CVSS v2:

  • Severity: Medium
  • Score: 6.8
  • AV:N/AC:M/Au:N/C:P/I:P/A:P
Software From Fixed in
mozilla / firefox 0.1 0.1.x
mozilla / firefox 0.9_rc 0.9_rc.x
mozilla / firefox 0.8 0.8.x
mozilla / firefox 1.5-beta2 1.5-beta2.x
mozilla / firefox 3.0.7 3.0.7.x
mozilla / firefox 1.5.2 1.5.2.x
mozilla / firefox - 3.0.9.x
mozilla / firefox 1.5.0.6 1.5.0.6.x
mozilla / firefox 1.8 1.8.x
mozilla / firefox 1.5.0.10 1.5.0.10.x
mozilla / firefox 1.5.0.3 1.5.0.3.x
mozilla / firefox 1.5.0.11 1.5.0.11.x
mozilla / firefox 1.4.1 1.4.1.x
mozilla / firefox 1.5.4 1.5.4.x
mozilla / firefox 1.0.2 1.0.2.x
mozilla / firefox 3.0.4 3.0.4.x
mozilla / firefox 1.5-beta1 1.5-beta1.x
mozilla / firefox 2.0_8 2.0_8.x
mozilla / firefox 2.0_.9 2.0_.9.x
mozilla / firefox 3.0.5 3.0.5.x
mozilla / firefox 1.5 1.5.x
mozilla / firefox 0.9.1 0.9.1.x
mozilla / firefox 1.0.4 1.0.4.x
mozilla / firefox 2.0.0.7 2.0.0.7.x
mozilla / firefox 1.0.7 1.0.7.x
mozilla / firefox 2.0.0.9 2.0.0.9.x
mozilla / firefox 0.10.1 0.10.1.x
mozilla / firefox 2.0_.1 2.0_.1.x
mozilla / firefox 0.9 0.9.x
mozilla / firefox 2.0.0.16 2.0.0.16.x
mozilla / firefox 1.5.6 1.5.6.x
mozilla / firefox 2.0.0.17 2.0.0.17.x
mozilla / firefox 0.7 0.7.x
mozilla / firefox 3.0.10 3.0.10.x
mozilla / firefox 0.2 0.2.x
mozilla / firefox 0.3 0.3.x
mozilla / firefox 2.0_.10 2.0_.10.x
mozilla / firefox 1.0 1.0.x
mozilla / firefox 3.0.3 3.0.3.x
mozilla / firefox 1.5.0.7 1.5.0.7.x
mozilla / firefox 2.0 2.0.x
mozilla / firefox 1.0.1 1.0.1.x
mozilla / firefox 2.0-beta1 2.0-beta1.x
mozilla / firefox 2.0.0.14 2.0.0.14.x
mozilla / firefox 0.6 0.6.x
mozilla / firefox 0.7.1 0.7.1.x
mozilla / firefox 3.0.6 3.0.6.x
mozilla / firefox 1.5.0.8 1.5.0.8.x
mozilla / firefox 2.0.0.3 2.0.0.3.x
mozilla / firefox 1.5.0.9 1.5.0.9.x
mozilla / firefox 1.5.0.5 1.5.0.5.x
mozilla / firefox 1.5.7 1.5.7.x
mozilla / firefox 1.5.0.12 1.5.0.12.x
mozilla / firefox 3.0 3.0.x
mozilla / firefox 2.0.0.11 2.0.0.11.x
mozilla / firefox 1.5.0.2 1.5.0.2.x
mozilla / firefox 1.0.3 1.0.3.x
mozilla / firefox 0.5 0.5.x
mozilla / firefox 0.6.1 0.6.1.x
mozilla / firefox 1.5.1 1.5.1.x
mozilla / firefox 2.0.0.21 2.0.0.21.x
mozilla / firefox 0.9.3 0.9.3.x
mozilla / firefox 2.0.0.13 2.0.0.13.x
mozilla / firefox 2.0.0.18 2.0.0.18.x
mozilla / firefox 3.0.2 3.0.2.x
mozilla / firefox 2.0_.6 2.0_.6.x
mozilla / firefox 2.0_.4 2.0_.4.x
mozilla / firefox 0.9.2 0.9.2.x
mozilla / firefox 1.0-preview_release 1.0-preview_release.x
mozilla / firefox 2.0-beta_1 2.0-beta_1.x
mozilla / firefox 2.0.0.20 2.0.0.20.x
mozilla / firefox 2.0.0.8 2.0.0.8.x
mozilla / firefox 0.9-rc 0.9-rc.x
mozilla / firefox 2.0.0.19 2.0.0.19.x
mozilla / firefox 1.5.8 1.5.8.x
mozilla / firefox 1.5.3 1.5.3.x
mozilla / firefox 0.4 0.4.x
mozilla / firefox 1.5.0.4 1.5.0.4.x
mozilla / firefox 1.5.0.1 1.5.0.1.x
mozilla / firefox 0.10 0.10.x
mozilla / firefox 1.0.5 1.0.5.x
mozilla / firefox 2.0.0.5 2.0.0.5.x
mozilla / firefox 2.0.0.10 2.0.0.10.x
mozilla / firefox 2.0-rc3 2.0-rc3.x
mozilla / firefox 1.0.6 1.0.6.x
mozilla / firefox 1.0.8 1.0.8.x