CVE-2008-0594
published 2008-02-09CVE-2008-0594: Mozilla Firefox before 2.0.0.12 does not always display a web forgery warning dialog if the entire contents of a web page are in a DIV tag that uses absolute…
PriorityP418medium5CVSS 2.0
AVNACLAuNCNIPAN
EPSS
1.97%
78.4th percentile
Mozilla Firefox before 2.0.0.12 does not always display a web forgery warning dialog if the entire contents of a web page are in a DIV tag that uses absolute positioning, which makes it easier for remote attackers to conduct phishing attacks.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 2.0.0.11 | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
vendor_ubuntu9.3CRITICAL
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2008-02-08·CVSS 9.3
CVE-2008-0412 [CRITICAL] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox vulnerabilities
Various flaws were discovered in the browser and JavaScript engine.
By tricking a user into opening a malicious web page, an attacker
could execute arbitrary code with the user's privileges.
(CVE-2008-0412, CVE-2008-0413)
Flaws were discovered in the file upload form control. A malicious
website could force arbitrary files from the user's computer to be
uploaded without consent. (CVE-2008-0414)
Various flaws were discovered in the JavaScript engine. By tricking
a user into opening a malicious web page, an attacker could escalate
privileges within the browser, perform cross-site scripting attacks
and/or execute arbitrary code with the user's privileges. (CVE-2008-0415)
Various flaws were discovered in character encoding ha
Red Hat
mozilla: web forgery warning may not be displayed
vendor_redhat·2008-02-07·CVSS 5.0
CVE-2008-0594 [MEDIUM] mozilla: web forgery warning may not be displayed
mozilla: web forgery warning may not be displayed
Mozilla Firefox before 2.0.0.12 does not always display a web forgery warning dialog if the entire contents of a web page are in a DIV tag that uses absolute positioning, which makes it easier for remote attackers to conduct phishing attacks.
Statement: Not vulnerable.
This does not affect the versions of Firefox or SeaMonkey shipped in Red Hat Enterprise Linux.
GHSA
GHSA-7wr6-m3x7-mq75: Mozilla Firefox before 2
ghsa_unreviewed·2022-05-01
CVE-2008-0594 [MEDIUM] GHSA-7wr6-m3x7-mq75: Mozilla Firefox before 2
Mozilla Firefox before 2.0.0.12 does not always display a web forgery warning dialog if the entire contents of a web page are in a DIV tag that uses absolute positioning, which makes it easier for remote attackers to conduct phishing attacks.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2008-3112 Java Web Start, arbitrary file creation (6703909)
bugzilla·2008-07-09·CVSS 10.0
CVE-2008-3112 [CRITICAL] CVE-2008-3112 Java Web Start, arbitrary file creation (6703909)
CVE-2008-3112 Java Web Start, arbitrary file creation (6703909)
Sunalert, 238905, Second Issue
A vulnerability in Java Web Start may allow an untrusted Java Web Start
application downloaded from a website to create arbitrary files with the
permissions of the user running the untrusted Java Web Start application.
Discussion:
This was resolved via:
http://rhn.redhat.com/errata/RHSA-2008-0595.html (RHEL4, RHEL5)
http://rhn.redhat.com/errata/RHSA-2008-0955.html (RHEL3, RHEL4, RHEL5)
http://rhn.redhat.com/errata/RHSA-2008-0790.html (RHEL4, RHEL5)
http://rhn.redhat.com/errata/RHSA-2008-0636.html (Satellite 5.1)
http://rhn.redhat.com/errata/RHSA-2008-0638.html (Satellite 5.1)
http://rhn.redhat.com/errata/RHSA-2008-0906.html (RHEL4, RHEL5)
http://rhn.redhat.com/errata/RHSA-2008-0594.html (RHE
Bugzilla
CVE-2008-3114 Java Web Start, untrusted application may determine Cache Location (6704074)
bugzilla·2008-07-09·CVSS 5.0
CVE-2008-3114 [MEDIUM] CVE-2008-3114 Java Web Start, untrusted application may determine Cache Location (6704074)
CVE-2008-3114 Java Web Start, untrusted application may determine Cache Location (6704074)
Sunalert, 238905, Fourth Issue
A vulnerability in Java Web Start may allow an untrusted Java Web Start
application to determine the location of the Java Web Start cache.
Discussion:
This was resolved via:
http://rhn.redhat.com/errata/RHSA-2008-0595.html (RHEL4, RHEL5)
http://rhn.redhat.com/errata/RHSA-2008-0955.html (RHEL3, RHEL4, RHEL5)
http://rhn.redhat.com/errata/RHSA-2008-0790.html (RHEL4, RHEL5)
http://rhn.redhat.com/errata/RHSA-2008-0636.html (Satellite 5.1)
http://rhn.redhat.com/errata/RHSA-2008-0638.html (Satellite 5.1)
http://rhn.redhat.com/errata/RHSA-2008-0906.html (RHEL4, RHEL5)
http://rhn.redhat.com/errata/RHSA-2008-0594.html (RHEL4, RHEL5)
Bugzilla
CVE-2008-3109 CVE-2008-3110 Security Vulnerabilities in the Java Runtime Environment Scripting Language Support (6529568, 6529579)
bugzilla·2008-07-09·CVSS 7.5
CVE-2008-3109 [HIGH] CVE-2008-3109 CVE-2008-3110 Security Vulnerabilities in the Java Runtime Environment Scripting Language Support (6529568, 6529579)
CVE-2008-3109 CVE-2008-3110 Security Vulnerabilities in the Java Runtime Environment Scripting Language Support (6529568, 6529579)
A vulnerability in the Java Runtime Environment relating to scripting language
support may allow an untrusted applet or application to elevate its privileges.
For example, an untrusted applet may grant itself permissions to read and write
local files or execute local applications that are accessible to the user
running the untrusted applet.
A second vulnerability in the Java Runtime Environment relating to scripting
language support may allow an untrusted applet to access information from
another applet.
Discussion:
This issue has been addressed via:
RHEL Supplementary version 5 (RHSA-2008:0594 (java-1.6.0-sun) and RHSA-2008:0906 (java-1.6.0-ibm))
Red Hat
Bugzilla
CVE-2008-0594 mozilla: web forgery warning may not be displayed
bugzilla·2008-02-08·CVSS 5.0
CVE-2008-0594 [MEDIUM] CVE-2008-0594 mozilla: web forgery warning may not be displayed
CVE-2008-0594 mozilla: web forgery warning may not be displayed
MFSA 2008-11 [1]:
Security researchers Emil Ljungdahl and Lars-Olof Moilanen demonstrated that, in
cases where the entire contents of a page are enclosed in a with absolute
positioning, a web forgery warning dialog won't be displayed unless the user
switches tabs away-from then back-to the forgery page.
[1] http://www.mozilla.org/security/announce/2008/mfsa2008-11.html
Fixed upstream in firefox 2.0.0.12.
Discussion:
blam-1.8.3-13.fc8,chmsee-1.0.0-1.28.fc8,devhelp-0.16.1-5.fc8,epiphany-2.20.2-3.fc8,epiphany-extensions-2.20.1-5.fc8,firefox-2.0.0.12-1.fc8,galeon-2.0.4-1.fc8.2,gnome-python2-extras-2.19.1-12.fc8,gnome-web-photo-0.3-8.fc8,gtkmozembedmm-1.4.2.cvs20060817-18.fc8,kazehakase-0.5.2-1.fc8.2,liferea-1.4.11-2.fc8,Miro
http://browser.netscape.com/releasenotes/http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00006.htmlhttp://secunia.com/advisories/28864http://secunia.com/advisories/28865http://secunia.com/advisories/28877http://secunia.com/advisories/28879http://secunia.com/advisories/28924http://secunia.com/advisories/28939http://secunia.com/advisories/28958http://secunia.com/advisories/29086http://secunia.com/advisories/29567http://secunia.com/advisories/30327http://secunia.com/advisories/30620http://sunsolve.sun.com/search/document.do?assetkey=1-26-238492-1http://support.novell.com/techcenter/psdb/6251b18e050302ebe7fe74294b55c818.htmlhttp://wiki.rpath.com/Advisories:rPSA-2008-0051http://www.debian.org/security/2008/dsa-1484http://www.debian.org/security/2008/dsa-1485http://www.debian.org/security/2008/dsa-1489http://www.debian.org/security/2008/dsa-1506http://www.gentoo.org/security/en/glsa/glsa-200805-18.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2008:048http://www.mozilla.org/security/announce/2008/mfsa2008-11.htmlhttp://www.securityfocus.com/archive/1/487826/100/0/threadedhttp://www.securityfocus.com/archive/1/488002/100/0/threadedhttp://www.securityfocus.com/bid/27683http://www.securitytracker.com/id?1019342http://www.ubuntu.com/usn/usn-576-1http://www.vupen.com/english/advisories/2008/0453/referenceshttp://www.vupen.com/english/advisories/2008/0627/referenceshttp://www.vupen.com/english/advisories/2008/1793/referenceshttps://bugzilla.mozilla.org/show_bug.cgi?id=408164https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00274.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-February/msg00381.htmlhttp://browser.netscape.com/releasenotes/http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00006.htmlhttp://secunia.com/advisories/28864http://secunia.com/advisories/28865http://secunia.com/advisories/28877http://secunia.com/advisories/28879http://secunia.com/advisories/28924http://secunia.com/advisories/28939http://secunia.com/advisories/28958http://secunia.com/advisories/29086http://secunia.com/advisories/29567http://secunia.com/advisories/30327http://secunia.com/advisories/30620http://sunsolve.sun.com/search/document.do?assetkey=1-26-238492-1http://support.novell.com/techcenter/psdb/6251b18e050302ebe7fe74294b55c818.htmlhttp://wiki.rpath.com/Advisories:rPSA-2008-0051http://www.debian.org/security/2008/dsa-1484http://www.debian.org/security/2008/dsa-1485http://www.debian.org/security/2008/dsa-1489http://www.debian.org/security/2008/dsa-1506http://www.gentoo.org/security/en/glsa/glsa-200805-18.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2008:048http://www.mozilla.org/security/announce/2008/mfsa2008-11.htmlhttp://www.securityfocus.com/archive/1/487826/100/0/threadedhttp://www.securityfocus.com/archive/1/488002/100/0/threadedhttp://www.securityfocus.com/bid/27683http://www.securitytracker.com/id?1019342http://www.ubuntu.com/usn/usn-576-1http://www.vupen.com/english/advisories/2008/0453/referenceshttp://www.vupen.com/english/advisories/2008/0627/referenceshttp://www.vupen.com/english/advisories/2008/1793/referenceshttps://bugzilla.mozilla.org/show_bug.cgi?id=408164https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00274.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-February/msg00381.html
2008-02-09
Published