CVE-2008-5510
The CSS parser in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 ignores the '\0' escaped null character, which might allow remote attackers to bypass protection mechanisms such…
Does this matter?
Lower severity and a low EPSS score (2.21%). Track it; it rarely justifies an emergency change on its own.
Description
The CSS parser in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 ignores the '\0' escaped null character, which might allow remote attackers to bypass protection mechanisms such as sanitization routines.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
- EPSS
- 2.21% probability · 82th percentile
- CISA KEV
- Not listed
- Affected
- mozilla/firefox · mozilla/seamonkey · mozilla/thunderbird · canonical/ubuntu linux · debian/debian linux
- Source
- secalert@redhat.com
References
- http://secunia.com/advisories/33184Third Party Advisory
- http://secunia.com/advisories/33188Third Party Advisory
- http://secunia.com/advisories/33203Third Party Advisory
- http://secunia.com/advisories/33204Third Party Advisory
- http://secunia.com/advisories/33205Third Party Advisory
- http://secunia.com/advisories/33216Third Party Advisory
- http://secunia.com/advisories/33231Third Party Advisory
- http://secunia.com/advisories/33408Third Party Advisory
- http://secunia.com/advisories/33523Third Party Advisory
- http://secunia.com/advisories/34501Third Party Advisory
- http://secunia.com/advisories/35080Third Party Advisory
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-256408-1Broken Link
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-258748-1Broken Link
- http://www.debian.org/security/2009/dsa-1707Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:244Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:245Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:012Third Party Advisory
- http://www.mozilla.org/security/announce/2008/mfsa2008-67.htmlVendor Advisory
- http://www.redhat.com/support/errata/RHSA-2008-1036.htmlThird Party Advisory
- http://www.securityfocus.com/bid/32882Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1021425Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/usn-690-2Third Party Advisory
- http://www.ubuntu.com/usn/usn-701-1Third Party Advisory
- http://www.vupen.com/english/advisories/2009/0977Third Party Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=228856Issue Tracking, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/47415Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9662Third Party Advisory
- https://usn.ubuntu.com/690-1/Third Party Advisory
- http://secunia.com/advisories/33184Third Party Advisory
- http://secunia.com/advisories/33188Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.