CVE-2008-0416
published 2008-02-12CVE-2008-0416: Multiple cross-site scripting (XSS) vulnerabilities in Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8 allow remote…
PriorityP416medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.62%
73.4th percentile
Multiple cross-site scripting (XSS) vulnerabilities in Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8 allow remote attackers to inject arbitrary web script or HTML via certain character encodings, including (1) a backspace character that is treated as whitespace, (2) 0x80 with Shift_JIS encoding, and (3) "zero-length non-ASCII sequences" in certain Asian character sets.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 2.0.0.11 | — |
| mozilla | seamonkey | <= 1.1.7 | — |
| mozilla | thunderbird | <= 2.0.0.11 | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_ubuntu9.3CRITICAL
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2h42-qmq7-j2qx: Multiple cross-site scripting (XSS) vulnerabilities in Mozilla Firefox before 2
ghsa_unreviewed·2022-05-01
CVE-2008-0416 [MEDIUM] CWE-79 GHSA-2h42-qmq7-j2qx: Multiple cross-site scripting (XSS) vulnerabilities in Mozilla Firefox before 2
Multiple cross-site scripting (XSS) vulnerabilities in Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8 allow remote attackers to inject arbitrary web script or HTML via certain character encodings, including (1) a backspace character that is treated as whitespace, (2) 0x80 with Shift_JIS encoding, and (3) "zero-length non-ASCII sequences" in certain Asian character sets.
Kernel
namei: allow restricted O_CREAT of FIFOs and regular files
kernel_security·2018-08-23·CVSS 7.2
CVE-2000-1134 [HIGH] namei: allow restricted O_CREAT of FIFOs and regular files
namei: allow restricted O_CREAT of FIFOs and regular files
Disallows open of FIFOs or regular files not owned by the user in world
writable sticky directories, unless the owner is the same as that of the
directory or the file is opened without the O_CREAT flag. The purpose
is to make data spoofing attacks harder. This protection can be turned
on and off separately for FIFOs and regular files via sysctl, just like
the symlinks/hardlinks protection. This patch is based on Openwall's
"HARDEN_FIFO" feature by Solar Designer.
This is a brief list of old vulnerabilities that could have been prevented
by this feature, some of them even allow for privilege escalation:
CVE-2000-1134
CVE-2007-3852
CVE-2008-0525
CVE-2009-0416
CVE-2011-4834
CVE-2015-1838
CVE-2015-7442
CVE-2016-7489
This list is no
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2008-03-26·CVSS 5.0
CVE-2008-1241 [MEDIUM] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox vulnerabilities
Alexey Proskuryakov, Yosuke Hasegawa and Simon Montagu discovered flaws
in Firefox's character encoding handling. If a user were tricked into
opening a malicious web page, an attacker could perform cross-site
scripting attacks. (CVE-2008-0416)
Various flaws were discovered in the JavaScript engine. By tricking
a user into opening a malicious web page, an attacker could escalate
privileges within the browser, perform cross-site scripting attacks
and/or execute arbitrary code with the user's privileges.
(CVE-2008-1233, CVE-2008-1234, CVE-2008-1235)
Several problems were discovered in Firefox which could lead to crashes
and memory corruption. If a user were tricked into opening a malicious
web page, an attacker may be able to
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2008-02-08·CVSS 9.3
CVE-2008-0412 [CRITICAL] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox vulnerabilities
Various flaws were discovered in the browser and JavaScript engine.
By tricking a user into opening a malicious web page, an attacker
could execute arbitrary code with the user's privileges.
(CVE-2008-0412, CVE-2008-0413)
Flaws were discovered in the file upload form control. A malicious
website could force arbitrary files from the user's computer to be
uploaded without consent. (CVE-2008-0414)
Various flaws were discovered in the JavaScript engine. By tricking
a user into opening a malicious web page, an attacker could escalate
privileges within the browser, perform cross-site scripting attacks
and/or execute arbitrary code with the user's privileges. (CVE-2008-0415)
Various flaws were discovered in character encoding ha
Red Hat
Mozilla arbitrary code execution
vendor_redhat·2008-02-07·CVSS 4.3
CVE-2008-0416 [MEDIUM] Mozilla arbitrary code execution
Mozilla arbitrary code execution
Multiple cross-site scripting (XSS) vulnerabilities in Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8 allow remote attackers to inject arbitrary web script or HTML via certain character encodings, including (1) a backspace character that is treated as whitespace, (2) 0x80 with Shift_JIS encoding, and (3) "zero-length non-ASCII sequences" in certain Asian character sets.
No detection rules found.
No public exploits indexed.
http://jvn.jp/en/jp/JVN21563357/index.htmlhttp://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-000021.htmlhttp://secunia.com/advisories/28839http://secunia.com/advisories/28864http://secunia.com/advisories/28865http://secunia.com/advisories/28879http://secunia.com/advisories/29541http://secunia.com/advisories/30327http://secunia.com/advisories/30620http://secunia.com/advisories/31043http://sunsolve.sun.com/search/document.do?assetkey=1-26-238492-1http://sunsolve.sun.com/search/document.do?assetkey=1-26-239546-1http://www.debian.org/security/2008/dsa-1484http://www.debian.org/security/2008/dsa-1485http://www.debian.org/security/2008/dsa-1489http://www.gentoo.org/security/en/glsa/glsa-200805-18.xmlhttp://www.mozilla.org/security/announce/2008/mfsa2008-13.htmlhttp://www.securityfocus.com/bid/29303http://www.turbolinux.com/security/2008/TLSA-2008-9.txthttp://www.ubuntu.com/usn/usn-592-1http://www.us-cert.gov/cas/techalerts/TA08-087A.htmlhttp://www.vupen.com/english/advisories/2008/1793/referenceshttp://www.vupen.com/english/advisories/2008/2091/referenceshttps://bugzilla.mozilla.org/buglist.cgi?bug_id=404252%2C381412%2C407161https://exchange.xforce.ibmcloud.com/vulnerabilities/40488https://usn.ubuntu.com/576-1/http://jvn.jp/en/jp/JVN21563357/index.htmlhttp://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-000021.htmlhttp://secunia.com/advisories/28839http://secunia.com/advisories/28864http://secunia.com/advisories/28865http://secunia.com/advisories/28879http://secunia.com/advisories/29541http://secunia.com/advisories/30327http://secunia.com/advisories/30620http://secunia.com/advisories/31043http://sunsolve.sun.com/search/document.do?assetkey=1-26-238492-1http://sunsolve.sun.com/search/document.do?assetkey=1-26-239546-1http://www.debian.org/security/2008/dsa-1484http://www.debian.org/security/2008/dsa-1485http://www.debian.org/security/2008/dsa-1489http://www.gentoo.org/security/en/glsa/glsa-200805-18.xmlhttp://www.mozilla.org/security/announce/2008/mfsa2008-13.htmlhttp://www.securityfocus.com/bid/29303http://www.turbolinux.com/security/2008/TLSA-2008-9.txthttp://www.ubuntu.com/usn/usn-592-1http://www.us-cert.gov/cas/techalerts/TA08-087A.htmlhttp://www.vupen.com/english/advisories/2008/1793/referenceshttp://www.vupen.com/english/advisories/2008/2091/referenceshttps://bugzilla.mozilla.org/buglist.cgi?bug_id=404252%2C381412%2C407161https://exchange.xforce.ibmcloud.com/vulnerabilities/40488https://usn.ubuntu.com/576-1/
2008-02-12
Published