CVE-2009-2408

Mozilla Network Security Services (NSS) before 3.12.3, Firefox before 3.0.13, Thunderbird before 2.0.0.23, and SeaMonkey before 1.1.18 do not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority. NOTE: this was originally reported for Firefox before 3.5.

Published: 2009-07-30 Last update: 2026-06-16 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2009-2408 is rated Moderate Risk (59.7/100): CVSS Medium severity, with high exploitation likelihood (EPSS 5.74%, 92th percentile). Core evidence: EPSS ranks this CVE among the most likely to be exploited in the near term. EPSS rose +3.89% over the last day, indicating growing attacker interest. Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2009-2408

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-06-15 1.85% 5.74% +3.89%
2 2026-04-17 3.36% 1.85% -1.51%
3 2026-04-14 3.36%

Full EPSS history (43 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2009-2408

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
5.9 3.1 MEDIUM
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N Click to expand
Attack vector (AV:N)
Could be attacked over the internet or any normal routed network—not just someone sitting at the machine.
Attack complexity (AC:H)
Even with access, the exploit needs extra luck, timing, or a fussy environment to actually work.
Privileges required (PR:N)
No account or special rights needed—anonymous or random user is enough.
User interaction (UI:N)
Nobody has to click “OK” or open a trap file; it can work without a victim helping.
Scope (S:U)
Damage stays in the same “trust bubble” as the broken component—no big spill into unrelated systems.
Confidentiality (C:N)
Doesn’t really leak secrets in a meaningful way.
Integrity (I:H)
They could widely tamper with or forge data—trust in the data is badly hurt.
Availability (A:N)
Service keeps running; no real outage angle.
2.2 3.6 [email protected]
6.8 2.0 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P Click to expand
Access vector (AV:N)
Can be exploited remotely over network reachability.
Access complexity (AC:M)
Exploitation needs some favorable conditions, but not exceptional ones.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:P)
Partial confidentiality impact.
Integrity impact (I:P)
Partial integrity impact.
Availability impact (A:P)
Partial availability impact.
8.6 6.4 [email protected]

Weakness enumeration for CVE-2009-2408

OS Trackers for CVE-2009-2408

vendor priority summary link
debian medium CVE-2009-2408 medium priority: Debian including 1 source packages (nss), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. https://security-tracker.debian.org/tracker/CVE-2009-2408
gentoo high CVE-2009-2408: 1 GLSA(s) (201301-01), 14 atom(s) (dev-libs/nss, mail-client/mozilla-thunderbird, …); latest impact high. https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2009-2408
redhat high https://access.redhat.com/security/cve/CVE-2009-2408
ubuntu medium CVE-2009-2408 medium priority: Ubuntu including 5 source packages (nss, openssl, xulrunner, xulrunner-1.9, xulrunner-1.9.1), 25 status rows across 5 suites (dapper, hardy, intrepid, jaunty, upstream): not-affected 12, DNE 6, released 4, needs-triage 3. https://ubuntu.com/security/CVE-2009-2408

Affected software / configurations for CVE-2009-2408

Vendor Product Version Raw CPE
mozilla firefox < 3.0.13 cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
mozilla network_security_services < 3.12.3 cpe:2.3:a:mozilla:network_security_services:*:*:*:*:*:*:*:*
mozilla seamonkey < 1.1.18 cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:*
mozilla thunderbird < 2.0.0.23 cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
opensuse opensuse >= 10.3, <= 11.1 cpe:2.3:o:opensuse:opensuse:*:*:*:*:*:*:*:*
suse linux_enterprise 10.0 cpe:2.3:o:suse:linux_enterprise:10.0:-:*:*:*:*:*:*
suse linux_enterprise 11.0 cpe:2.3:o:suse:linux_enterprise:11.0:-:*:*:*:*:*:*
suse linux_enterprise_server 9 cpe:2.3:o:suse:linux_enterprise_server:9:*:*:*:*:*:*:*
debian debian_linux 5.0 cpe:2.3:o:debian:debian_linux:5.0:*:*:*:*:*:*:*
canonical ubuntu_linux 8.04 cpe:2.3:o:canonical:ubuntu_linux:8.04:*:*:*:-:*:*:*
canonical ubuntu_linux 8.10 cpe:2.3:o:canonical:ubuntu_linux:8.10:*:*:*:*:*:*:*
canonical ubuntu_linux 9.04 cpe:2.3:o:canonical:ubuntu_linux:9.04:*:*:*:*:*:*:*

References for CVE-2009-2408

URL Tags
http://isc.sans.org/diary.html?storyid=7003 Broken Link
http://lists.opensuse.org/opensuse-security-announce/2009-11/msg00004.html Mailing List
http://marc.info/?l=oss-security&m=125198917018936&w=2 Mailing List
http://osvdb.org/56723 Broken Link
http://secunia.com/advisories/36088 Broken Link Vendor Advisory
http://secunia.com/advisories/36125 Broken Link Vendor Advisory
http://secunia.com/advisories/36139 Broken Link Vendor Advisory
http://secunia.com/advisories/36157 Broken Link Vendor Advisory
http://secunia.com/advisories/36434 Broken Link Vendor Advisory
http://secunia.com/advisories/36669 Broken Link
http://secunia.com/advisories/37098 Broken Link
http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021030.1-1 Broken Link
http://www.debian.org/security/2009/dsa-1874 Mailing List
http://www.mandriva.com/security/advisories?name=MDVSA-2009:197 Broken Link
http://www.mandriva.com/security/advisories?name=MDVSA-2009:216 Broken Link
http://www.mandriva.com/security/advisories?name=MDVSA-2009:217 Broken Link
http://www.mozilla.org/security/announce/2009/mfsa2009-42.html Vendor Advisory
http://www.novell.com/linux/security/advisories/2009_48_firefox.html Broken Link
http://www.openldap.org/devel/cvsweb.cgi/libraries/libldap/tls_m.c.diff?r1=1.8&r2=1.11&f=h Broken Link
http://www.redhat.com/support/errata/RHSA-2009-1207.html Broken Link
http://www.redhat.com/support/errata/RHSA-2009-1432.html Broken Link
http://www.securitytracker.com/id?1022632 Broken Link Third Party Advisory VDB Entry
http://www.ubuntu.com/usn/usn-810-1 Third Party Advisory
http://www.vupen.com/english/advisories/2009/2085 Broken Link Vendor Advisory
http://www.vupen.com/english/advisories/2009/3184 Broken Link
http://www.wired.com/threatlevel/2009/07/kaminsky/ Press/Media Coverage
https://bugzilla.redhat.com/show_bug.cgi?id=510251 Issue Tracking
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10751 Broken Link
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8458 Broken Link
https://usn.ubuntu.com/810-2/ Broken Link
cvelogic Threat Intelligence