CVE-2008-5511
Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to bypass the same origin policy and conduct cross-site scripting (XSS) attacks via an XBL binding to an…
Does this matter?
Lower severity and a low EPSS score (1.86%). Track it; it rarely justifies an emergency change on its own.
Description
Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to bypass the same origin policy and conduct cross-site scripting (XSS) attacks via an XBL binding to an "unloaded document."
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 1.86% probability · 78th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- mozilla/firefox · mozilla/seamonkey · mozilla/thunderbird · canonical/ubuntu linux · debian/debian linux
- Source
- secalert@redhat.com
References
- http://secunia.com/advisories/33184Third Party Advisory
- http://secunia.com/advisories/33188Third Party Advisory
- http://secunia.com/advisories/33189Third Party Advisory
- http://secunia.com/advisories/33203Third Party Advisory
- http://secunia.com/advisories/33204Third Party Advisory
- http://secunia.com/advisories/33205Third Party Advisory
- http://secunia.com/advisories/33216Third Party Advisory
- http://secunia.com/advisories/33231Third Party Advisory
- http://secunia.com/advisories/33232Third Party Advisory
- http://secunia.com/advisories/33408Third Party Advisory
- http://secunia.com/advisories/33415Third Party Advisory
- http://secunia.com/advisories/33421Third Party Advisory
- http://secunia.com/advisories/33433Third Party Advisory
- http://secunia.com/advisories/33434Third Party Advisory
- http://secunia.com/advisories/33523Third Party Advisory
- http://secunia.com/advisories/33547Third Party Advisory
- http://secunia.com/advisories/34501Third Party Advisory
- http://secunia.com/advisories/35080Third Party Advisory
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-256408-1Broken Link
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-258748-1Broken Link
- http://www.debian.org/security/2009/dsa-1696Third Party Advisory
- http://www.debian.org/security/2009/dsa-1697Third Party Advisory
- http://www.debian.org/security/2009/dsa-1704Third Party Advisory
- http://www.debian.org/security/2009/dsa-1707Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:244Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:245Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:012Third Party Advisory
- http://www.mozilla.org/security/announce/2008/mfsa2008-68.htmlVendor Advisory
- http://www.redhat.com/support/errata/RHSA-2008-1036.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2008-1037.htmlThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.