CVE-2009-0358
Summary
| CVE | CVE-2009-0358 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-02-04 19:30:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Mozilla Firefox 3.x before 3.0.6 does not properly implement the (1) no-store and (2) no-cache Cache-Control directives, which allows local users to obtain sensitive information by using the (a) back button or (b) history list of the victim's browser, as demonstrated by reading the response page of an https POST request. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
AdjacentAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:A/AC:L/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Mozilla | Firefox | 3.0 | All | All | All |
| Application | Mozilla | Firefox | 3.0 | alpha | All | All |
| Application | Mozilla | Firefox | 3.0 | beta2 | All | All |
| Application | Mozilla | Firefox | 3.0 | beta5 | All | All |
| Application | Mozilla | Firefox | 3.0.1 | All | All | All |
| Application | Mozilla | Firefox | 3.0.2 | All | All | All |
| Application | Mozilla | Firefox | 3.0.3 | All | All | All |
| Application | Mozilla | Firefox | 3.0.4 | All | All | All |
| Application | Mozilla | Firefox | 3.0.5 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| Ubuntu update for firefox-3.0 and xulrunner-1.9 - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| USN-717-1: Firefox and Xulrunner vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| ASA-2009-040 (RHSA-2009-0256) | af854a3a-2127-422b-91ae-364da2661108 | support.avaya.com | |
| Support / Security / Advisories / / MDVSA-2009:044 | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| Avaya Products Mozilla Firefox Multiple Vulnerabilities - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Red Hat update for firefox - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| rhn.redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| Mozilla Firefox Does Not Properly Enforce Cache-Control Directives - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| Mozilla Firefox Multiple Vulnerabilities - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Mozilla Firefox/Thunderbird/SeaMonkey MFSA 2009 -01 to -06 Multiple Remote Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Fedora update for xulrunner - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Fedora update for firefox - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| [security-announce] SUSE Security Announcement: Mozilla Firefox (SUSE-SA | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Firefox 3 and the "cache-control" header | af854a3a-2127-422b-91ae-364da2661108 | blogs.imeta.co.uk | |
| [SECURITY] Fedora 9 Update: xulrunner-1.9.0.6-1.fc9 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| MFSA 2009-06: Directives to not cache pages ignored | af854a3a-2127-422b-91ae-364da2661108 | www.mozilla.org | Vendor Advisory |
| 441751 – (CVE-2009-0358) Directives not to cache pages ignored. | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.