Back to search
CVE-2008-0415
Published: Feb 8, 2008
Modified: Aug 7, 2024
PUBLISHED
Description
Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8 allows remote attackers to execute script outside of the sandbox and conduct cross-site scripting (XSS) attacks via multiple vectors including the XMLDocument.load function, aka "JavaScript privilege escalation bugs."
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
RHSA-2008:0104
vendor-advisory
x_refsource_REDHAT
USN-582-2
vendor-advisory
x_refsource_UBUNTU
USN-576-1
vendor-advisory
x_refsource_UBUNTU
http://browser.netscape.com/releasenotes/
x_refsource_CONFIRM
28939
third-party-advisory
x_refsource_SECUNIA
DSA-1506
vendor-advisory
x_refsource_DEBIAN
SSA:2008-061-01
vendor-advisory
x_refsource_SLACKWARE
https://issues.rpath.com/browse/RPL-1995
x_refsource_CONFIRM
FEDORA-2008-2118
vendor-advisory
x_refsource_FEDORA
FEDORA-2008-2060
vendor-advisory
x_refsource_FEDORA
http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0093
x_refsource_CONFIRM
28766
third-party-advisory
x_refsource_SECUNIA
28818
third-party-advisory
x_refsource_SECUNIA
30620
third-party-advisory
x_refsource_SECUNIA
28865
third-party-advisory
x_refsource_SECUNIA
29049
third-party-advisory
x_refsource_SECUNIA
ADV-2008-0453
vdb-entry
x_refsource_VUPEN
RHSA-2008:0103
vendor-advisory
x_refsource_REDHAT
28877
third-party-advisory
x_refsource_SECUNIA
28879
third-party-advisory
x_refsource_SECUNIA
USN-582-1
vendor-advisory
x_refsource_UBUNTU
29167
third-party-advisory
x_refsource_SECUNIA
29567
third-party-advisory
x_refsource_SECUNIA
RHSA-2008:0105
vendor-advisory
x_refsource_REDHAT
28958
third-party-advisory
x_refsource_SECUNIA
30327
third-party-advisory
x_refsource_SECUNIA
238492
vendor-advisory
x_refsource_SUNALERT
20080229 rPSA-2008-0093-1 thunderbird
mailing-list
x_refsource_BUGTRAQ
DSA-1489
vendor-advisory
x_refsource_DEBIAN
20080212 FLEA-2008-0001-1 firefox
mailing-list
x_refsource_BUGTRAQ
20080209 rPSA-2008-0051-1 firefox
mailing-list
x_refsource_BUGTRAQ
29086
third-party-advisory
x_refsource_SECUNIA
28815
third-party-advisory
x_refsource_SECUNIA
ADV-2008-0454
vdb-entry
x_refsource_VUPEN
239546
vendor-advisory
x_refsource_SUNALERT
28864
third-party-advisory
x_refsource_SECUNIA
oval:org.mitre.oval:def:9897
vdb-entry
signature
x_refsource_OVAL
DSA-1485
vendor-advisory
x_refsource_DEBIAN
28924
third-party-advisory
x_refsource_SECUNIA
27683
vdb-entry
x_refsource_BID
ADV-2008-1793
vdb-entry
x_refsource_VUPEN
http://www.mozilla.org/security/announce/2008/mfsa2008-03.html
x_refsource_CONFIRM
1019327
vdb-entry
x_refsource_SECTRACK
http://wiki.rpath.com/Advisories:rPSA-2008-0093
x_refsource_CONFIRM
ADV-2008-2091
vdb-entry
x_refsource_VUPEN
SUSE-SA:2008:008
vendor-advisory
x_refsource_SUSE
FEDORA-2008-1459
vendor-advisory
x_refsource_FEDORA
29164
third-party-advisory
x_refsource_SECUNIA
29211
third-party-advisory
x_refsource_SECUNIA
FEDORA-2008-1535
vendor-advisory
x_refsource_FEDORA
http://wiki.rpath.com/Advisories:rPSA-2008-0051
x_refsource_CONFIRM
MDVSA-2008:062
vendor-advisory
x_refsource_MANDRIVA
DSA-1484
vendor-advisory
x_refsource_DEBIAN
28808
third-party-advisory
x_refsource_SECUNIA
ADV-2008-0627
vdb-entry
x_refsource_VUPEN
GLSA-200805-18
vendor-advisory
x_refsource_GENTOO
28754
third-party-advisory
x_refsource_SECUNIA
28758
third-party-advisory
x_refsource_SECUNIA
FEDORA-2008-1435
vendor-advisory
x_refsource_FEDORA
MDVSA-2008:048
vendor-advisory
x_refsource_MANDRIVA
31043
third-party-advisory
x_refsource_SECUNIA
29098
third-party-advisory
x_refsource_SECUNIA
28839
third-party-advisory
x_refsource_SECUNIA
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now