CVE-2008-1233Code Injection in Mozilla Firefox

CWE-94Code Injection6 documents5 sources
Severity
6.8MEDIUMNVD
EPSS
19.9%
top 4.54%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 27
Latest updateMay 1

Description

Unspecified vulnerability in Mozilla Firefox before 2.0.0.13, Thunderbird before 2.0.0.13, and SeaMonkey before 1.1.9 allows remote attackers to execute arbitrary code via "XPCNativeWrapper pollution."

CVSS vector

AV:N/AC:M/C:P/I:P/A:PExploitability: 8.6 | Impact: 6.4

Affected Packages3 packages

NVDmozilla/firefox2.0.0.12
NVDmozilla/thunderbird2.0.0.12

🔴Vulnerability Details

1
GHSA
GHSA-5rxf-q5vv-56x5: Unspecified vulnerability in Mozilla Firefox before 22022-05-01

📋Vendor Advisories

3
Ubuntu
Thunderbird vulnerabilities2008-05-06
Ubuntu
Firefox vulnerabilities2008-03-26
Red Hat
Mozilla products XPCNativeWrapper pollution2008-03-25

💬Community

1
Bugzilla
CVE-2008-1233 Mozilla products XPCNativeWrapper pollution2008-03-24
CVE-2008-1233 — Code Injection in Mozilla Firefox | cvebase