SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2008-4065

Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allow remote attackers to bypass cross-site scripting (XSS) protection mechanisms and conduct XSS attacks via byte order mark (BOM) characters…

MEDIUM 4.3EPSS 4.11%

Does this matter?

Lower severity and a low EPSS score (4.11%). Track it; it rarely justifies an emergency change on its own.

Description

Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allow remote attackers to bypass cross-site scripting (XSS) protection mechanisms and conduct XSS attacks via byte order mark (BOM) characters that are removed from JavaScript code before execution, aka "Stripped BOM characters bug."

CVSS 2.0
4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS
4.11% probability · 90th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
mozilla/firefox · mozilla/seamonkey · mozilla/thunderbird · debian/debian linux · canonical/ubuntu linux
Source
secalert@redhat.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.