VulnerabilityModified
CVE-2008-5019
The session restore feature in Mozilla Firefox 3.x before 3.0.4 and 2.x before 2.0.0.18 allows remote attackers to violate the same origin policy to conduct cross-site scripting (XSS) attacks and execute arbitrary JavaScript with chrome privileges via…
MEDIUM 4.3EPSS 3.07%
Does this matter?
Lower severity and a low EPSS score (3.07%). Track it; it rarely justifies an emergency change on its own.
Description
The session restore feature in Mozilla Firefox 3.x before 3.0.4 and 2.x before 2.0.0.18 allows remote attackers to violate the same origin policy to conduct cross-site scripting (XSS) attacks and execute arbitrary JavaScript with chrome privileges via unknown vectors.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 3.07% probability · 87th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- mozilla/firefox · debian/debian linux · canonical/ubuntu linux
- Source
- secalert@redhat.com
References
- http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00004.htmlThird Party Advisory
- http://secunia.com/advisories/32684Third Party Advisory
- http://secunia.com/advisories/32693Third Party Advisory
- http://secunia.com/advisories/32694Third Party Advisory
- http://secunia.com/advisories/32695Third Party Advisory
- http://secunia.com/advisories/32713Third Party Advisory
- http://secunia.com/advisories/32721Third Party Advisory
- http://secunia.com/advisories/32778Third Party Advisory
- http://secunia.com/advisories/34501Third Party Advisory
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-256408-1Broken Link
- http://ubuntu.com/usn/usn-667-1Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:228Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:230Third Party Advisory
- http://www.mozilla.org/security/announce/2008/mfsa2008-53.htmlVendor Advisory
- http://www.redhat.com/support/errata/RHSA-2008-0977.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2008-0978.htmlThird Party Advisory
- http://www.securityfocus.com/bid/32281Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1021184Third Party Advisory, VDB Entry
- http://www.us-cert.gov/cas/techalerts/TA08-319A.htmlThird Party Advisory, US Government Resource
- http://www.vupen.com/english/advisories/2008/3146Third Party Advisory
- http://www.vupen.com/english/advisories/2009/0977Third Party Advisory
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=459906%2C460983
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10943Third Party Advisory
- https://www.redhat.com/archives/fedora-package-announce/2008-November/msg00366.htmlThird Party Advisory
- https://www.redhat.com/archives/fedora-package-announce/2008-November/msg00385.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00004.htmlThird Party Advisory
- http://secunia.com/advisories/32684Third Party Advisory
- http://secunia.com/advisories/32693Third Party Advisory
- http://secunia.com/advisories/32694Third Party Advisory
- http://secunia.com/advisories/32695Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.