CVE-2008-0417Code Injection in Mozilla Firefox

CWE-94Code Injection6 documents5 sources
Severity
4.3MEDIUMNVD
EPSS
2.1%
top 15.87%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 8
Latest updateMay 1

Description

CRLF injection vulnerability in Mozilla Firefox before 2.0.0.12 allows remote user-assisted web sites to corrupt the user's password store via newlines that are not properly handled when the user saves a password.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages1 packages

NVDmozilla/firefox2.0.0.11

🔴Vulnerability Details

1
GHSA
GHSA-x5ph-343m-g2xh: CRLF injection vulnerability in Mozilla Firefox before 22022-05-01

📋Vendor Advisories

2
Ubuntu
Firefox vulnerabilities2008-02-08
Red Hat
Mozilla arbitrary code execution2008-02-07

💬Community

2
Bugzilla
CVE-2010-0417 HelixPlayer / RealPlayer: rule book handling heap corruption2010-02-04
Bugzilla
CVE-2008-0417 Mozilla arbitrary code execution2008-02-06