CVE-2008-1238
published 2008-03-27CVE-2008-1238: Mozilla Firefox before 2.0.0.13 and SeaMonkey before 1.1.9, when generating the HTTP Referer header, does not list the entire URL when it contains Basic…
PriorityP423medium5CVSS 2.0
AVNACLAuNCNIPAN
EPSS
2.44%
82.6th percentile
Mozilla Firefox before 2.0.0.13 and SeaMonkey before 1.1.9, when generating the HTTP Referer header, does not list the entire URL when it contains Basic Authentication credentials without a username, which makes it easier for remote attackers to bypass application protection mechanisms that rely on Referer headers, such as with some Cross-Site Request Forgery (CSRF) mechanisms.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 2.0.0.12 | — |
| mozilla | seamonkey | <= 1.1.8 | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
vendor_redhat5.0MEDIUM
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-q345-fgmq-3pf3: Mozilla Firefox before 2
ghsa_unreviewed·2022-05-01
CVE-2008-1238 [MEDIUM] CWE-287 GHSA-q345-fgmq-3pf3: Mozilla Firefox before 2
Mozilla Firefox before 2.0.0.13 and SeaMonkey before 1.1.9, when generating the HTTP Referer header, does not list the entire URL when it contains Basic Authentication credentials without a username, which makes it easier for remote attackers to bypass application protection mechanisms that rely on Referer headers, such as with some Cross-Site Request Forgery (CSRF) mechanisms.
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2008-03-26·CVSS 5.0
CVE-2008-1241 [MEDIUM] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox vulnerabilities
Alexey Proskuryakov, Yosuke Hasegawa and Simon Montagu discovered flaws
in Firefox's character encoding handling. If a user were tricked into
opening a malicious web page, an attacker could perform cross-site
scripting attacks. (CVE-2008-0416)
Various flaws were discovered in the JavaScript engine. By tricking
a user into opening a malicious web page, an attacker could escalate
privileges within the browser, perform cross-site scripting attacks
and/or execute arbitrary code with the user's privileges.
(CVE-2008-1233, CVE-2008-1234, CVE-2008-1235)
Several problems were discovered in Firefox which could lead to crashes
and memory corruption. If a user were tricked into opening a malicious
web page, an attacker may be able to
Red Hat
Referrer spoofing bug
vendor_redhat·2008-03-25·CVSS 5.0
CVE-2008-1238 [MEDIUM] Referrer spoofing bug
Referrer spoofing bug
Mozilla Firefox before 2.0.0.13 and SeaMonkey before 1.1.9, when generating the HTTP Referer header, does not list the entire URL when it contains Basic Authentication credentials without a username, which makes it easier for remote attackers to bypass application protection mechanisms that rely on Referer headers, such as with some Cross-Site Request Forgery (CSRF) mechanisms.
No detection rules found.
http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00002.htmlhttp://rhn.redhat.com/errata/RHSA-2008-0208.htmlhttp://secunia.com/advisories/29391http://secunia.com/advisories/29526http://secunia.com/advisories/29539http://secunia.com/advisories/29541http://secunia.com/advisories/29547http://secunia.com/advisories/29550http://secunia.com/advisories/29558http://secunia.com/advisories/29560http://secunia.com/advisories/29607http://secunia.com/advisories/29616http://secunia.com/advisories/29645http://secunia.com/advisories/30327http://secunia.com/advisories/30620http://sla.ckers.org/forum/read.php?10%2C20033http://sunsolve.sun.com/search/document.do?assetkey=1-26-238492-1http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0128http://www.debian.org/security/2008/dsa-1532http://www.debian.org/security/2008/dsa-1534http://www.debian.org/security/2008/dsa-1535http://www.gentoo.org/security/en/glsa/glsa-200805-18.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2008:080http://www.mozilla.org/security/announce/2008/mfsa2008-16.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0207.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0209.htmlhttp://www.securityfocus.com/archive/1/490196/100/0/threadedhttp://www.securityfocus.com/bid/28448http://www.securitytracker.com/id?1019703http://www.ubuntu.com/usn/usn-592-1http://www.us-cert.gov/cas/techalerts/TA08-087A.htmlhttp://www.vupen.com/english/advisories/2008/0998/referenceshttp://www.vupen.com/english/advisories/2008/1793/referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/41449https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9889http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00002.htmlhttp://rhn.redhat.com/errata/RHSA-2008-0208.htmlhttp://secunia.com/advisories/29391http://secunia.com/advisories/29526http://secunia.com/advisories/29539http://secunia.com/advisories/29541http://secunia.com/advisories/29547http://secunia.com/advisories/29550http://secunia.com/advisories/29558http://secunia.com/advisories/29560http://secunia.com/advisories/29607http://secunia.com/advisories/29616http://secunia.com/advisories/29645http://secunia.com/advisories/30327http://secunia.com/advisories/30620http://sla.ckers.org/forum/read.php?10%2C20033http://sunsolve.sun.com/search/document.do?assetkey=1-26-238492-1http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0128http://www.debian.org/security/2008/dsa-1532http://www.debian.org/security/2008/dsa-1534http://www.debian.org/security/2008/dsa-1535http://www.gentoo.org/security/en/glsa/glsa-200805-18.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2008:080http://www.mozilla.org/security/announce/2008/mfsa2008-16.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0207.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0209.htmlhttp://www.securityfocus.com/archive/1/490196/100/0/threadedhttp://www.securityfocus.com/bid/28448http://www.securitytracker.com/id?1019703http://www.ubuntu.com/usn/usn-592-1http://www.us-cert.gov/cas/techalerts/TA08-087A.htmlhttp://www.vupen.com/english/advisories/2008/0998/referenceshttp://www.vupen.com/english/advisories/2008/1793/referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/41449https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9889
2008-03-27
Published