CVE-2008-1235
published 2008-03-27CVE-2008-1235: Unspecified vulnerability in Mozilla Firefox before 2.0.0.13, Thunderbird before 2.0.0.13, and SeaMonkey before 1.1.9 allows remote attackers to execute…
PriorityP344critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
6.05%
92.6th percentile
Unspecified vulnerability in Mozilla Firefox before 2.0.0.13, Thunderbird before 2.0.0.13, and SeaMonkey before 1.1.9 allows remote attackers to execute arbitrary code via unknown vectors that cause JavaScript to execute with the wrong principal, aka "Privilege escalation via incorrect principals."
Affected
100 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 2.0.0.12 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat9.3CRITICAL
vendor_ubuntu6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-q8g5-v4fw-48fq: Unspecified vulnerability in Mozilla Firefox before 2
ghsa_unreviewed·2022-05-01
CVE-2008-1235 [HIGH] GHSA-q8g5-v4fw-48fq: Unspecified vulnerability in Mozilla Firefox before 2
Unspecified vulnerability in Mozilla Firefox before 2.0.0.13, Thunderbird before 2.0.0.13, and SeaMonkey before 1.1.9 allows remote attackers to execute arbitrary code via unknown vectors that cause JavaScript to execute with the wrong principal, aka "Privilege escalation via incorrect principals."
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2008-05-06·CVSS 6.8
CVE-2008-1234 [MEDIUM] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Thunderbird vulnerabilities
Various flaws were discovered in the JavaScript engine. If a user had
JavaScript enabled and were tricked into opening a malicious email,
an attacker could escalate privileges within Thunderbird, perform
cross-site scripting attacks and/or execute arbitrary code with the
user's privileges. (CVE-2008-1233, CVE-2008-1234, CVE-2008-1235)
Several problems were discovered in Thunderbird which could lead to
crashes and memory corruption. If a user had JavaScript enabled and
were tricked into opening a malicious email, an attacker may be able
to execute arbitrary code with the user's privileges. (CVE-2008-1236,
CVE-2008-1237)
Instructions: After a standard system upgrade you need to restart Thunderbird to effect
the neces
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2008-03-26·CVSS 5.0
CVE-2008-1241 [MEDIUM] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox vulnerabilities
Alexey Proskuryakov, Yosuke Hasegawa and Simon Montagu discovered flaws
in Firefox's character encoding handling. If a user were tricked into
opening a malicious web page, an attacker could perform cross-site
scripting attacks. (CVE-2008-0416)
Various flaws were discovered in the JavaScript engine. By tricking
a user into opening a malicious web page, an attacker could escalate
privileges within the browser, perform cross-site scripting attacks
and/or execute arbitrary code with the user's privileges.
(CVE-2008-1233, CVE-2008-1234, CVE-2008-1235)
Several problems were discovered in Firefox which could lead to crashes
and memory corruption. If a user were tricked into opening a malicious
web page, an attacker may be able to
Red Hat
chrome privilege via wrong principal
vendor_redhat·2008-03-25·CVSS 9.3
CVE-2008-1235 [CRITICAL] chrome privilege via wrong principal
chrome privilege via wrong principal
Unspecified vulnerability in Mozilla Firefox before 2.0.0.13, Thunderbird before 2.0.0.13, and SeaMonkey before 1.1.9 allows remote attackers to execute arbitrary code via unknown vectors that cause JavaScript to execute with the wrong principal, aka "Privilege escalation via incorrect principals."
No detection rules found.
http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00002.htmlhttp://rhn.redhat.com/errata/RHSA-2008-0208.htmlhttp://secunia.com/advisories/29391http://secunia.com/advisories/29526http://secunia.com/advisories/29539http://secunia.com/advisories/29541http://secunia.com/advisories/29547http://secunia.com/advisories/29548http://secunia.com/advisories/29550http://secunia.com/advisories/29558http://secunia.com/advisories/29560http://secunia.com/advisories/29607http://secunia.com/advisories/29616http://secunia.com/advisories/29645http://secunia.com/advisories/30016http://secunia.com/advisories/30094http://secunia.com/advisories/30105http://secunia.com/advisories/30192http://secunia.com/advisories/30327http://secunia.com/advisories/30370http://secunia.com/advisories/30620http://secunia.com/advisories/31043http://sunsolve.sun.com/search/document.do?assetkey=1-26-238492-1http://sunsolve.sun.com/search/document.do?assetkey=1-26-239546-1http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0128http://www.debian.org/security/2008/dsa-1532http://www.debian.org/security/2008/dsa-1534http://www.debian.org/security/2008/dsa-1535http://www.debian.org/security/2008/dsa-1574http://www.gentoo.org/security/en/glsa/glsa-200805-18.xmlhttp://www.kb.cert.org/vuls/id/466521http://www.mandriva.com/security/advisories?name=MDVSA-2008:080http://www.mandriva.com/security/advisories?name=MDVSA-2008:155http://www.mozilla.org/security/announce/2008/mfsa2008-14.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0207.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0209.htmlhttp://www.securityfocus.com/archive/1/490196/100/0/threadedhttp://www.securityfocus.com/bid/28448http://www.securitytracker.com/id?1019694http://www.slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.447313http://www.ubuntu.com/usn/usn-592-1http://www.ubuntu.com/usn/usn-605-1http://www.us-cert.gov/cas/techalerts/TA08-087A.htmlhttp://www.vupen.com/english/advisories/2008/0998/referenceshttp://www.vupen.com/english/advisories/2008/0999/referenceshttp://www.vupen.com/english/advisories/2008/1793/referenceshttp://www.vupen.com/english/advisories/2008/2091/referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/41457https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10980https://www.redhat.com/archives/fedora-package-announce/2008-May/msg00058.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-May/msg00074.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-04/msg00002.htmlhttp://rhn.redhat.com/errata/RHSA-2008-0208.htmlhttp://secunia.com/advisories/29391http://secunia.com/advisories/29526http://secunia.com/advisories/29539http://secunia.com/advisories/29541http://secunia.com/advisories/29547http://secunia.com/advisories/29548http://secunia.com/advisories/29550http://secunia.com/advisories/29558http://secunia.com/advisories/29560http://secunia.com/advisories/29607http://secunia.com/advisories/29616http://secunia.com/advisories/29645http://secunia.com/advisories/30016http://secunia.com/advisories/30094http://secunia.com/advisories/30105http://secunia.com/advisories/30192http://secunia.com/advisories/30327http://secunia.com/advisories/30370http://secunia.com/advisories/30620http://secunia.com/advisories/31043http://sunsolve.sun.com/search/document.do?assetkey=1-26-238492-1http://sunsolve.sun.com/search/document.do?assetkey=1-26-239546-1http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0128http://www.debian.org/security/2008/dsa-1532http://www.debian.org/security/2008/dsa-1534http://www.debian.org/security/2008/dsa-1535http://www.debian.org/security/2008/dsa-1574http://www.gentoo.org/security/en/glsa/glsa-200805-18.xmlhttp://www.kb.cert.org/vuls/id/466521http://www.mandriva.com/security/advisories?name=MDVSA-2008:080http://www.mandriva.com/security/advisories?name=MDVSA-2008:155http://www.mozilla.org/security/announce/2008/mfsa2008-14.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0207.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0209.htmlhttp://www.securityfocus.com/archive/1/490196/100/0/threadedhttp://www.securityfocus.com/bid/28448http://www.securitytracker.com/id?1019694http://www.slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.447313http://www.ubuntu.com/usn/usn-592-1http://www.ubuntu.com/usn/usn-605-1http://www.us-cert.gov/cas/techalerts/TA08-087A.htmlhttp://www.vupen.com/english/advisories/2008/0998/referenceshttp://www.vupen.com/english/advisories/2008/0999/referenceshttp://www.vupen.com/english/advisories/2008/1793/referenceshttp://www.vupen.com/english/advisories/2008/2091/referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/41457https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10980
+ 2 more references
2008-03-27
Published