SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2008-5507

Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allow remote attackers to bypass the same origin policy and access portions of data from another domain via a JavaScript URL that…

MEDIUM 6.0EPSS 1.66%

Does this matter?

Lower severity and a low EPSS score (1.66%). Track it; it rarely justifies an emergency change on its own.

Description

Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allow remote attackers to bypass the same origin policy and access portions of data from another domain via a JavaScript URL that redirects to the target resource, which generates an error if the target data does not have JavaScript syntax, which can be accessed using the window.onerror DOM API.

CVSS 2.0
6.0 MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:P
EPSS
1.66% probability · 75th percentile
CISA KEV
Not listed
Weakness
CWE-200
Affected
mozilla/firefox · mozilla/seamonkey · mozilla/thunderbird · canonical/ubuntu linux · debian/debian linux
Source
secalert@redhat.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.