CVE-2008-2801
published 2008-07-07CVE-2008-2801: Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 do not properly implement JAR signing, which allows remote attackers to execute arbitrary code via…
PriorityP336high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
2.81%
84.9th percentile
Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 do not properly implement JAR signing, which allows remote attackers to execute arbitrary code via (1) injection of JavaScript into documents within a JAR archive or (2) a JAR archive that uses relative URLs to JavaScript files.
Affected
40 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 2.0.0.14 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | seamonkey | <= 1.1.9 | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_ubuntu10.0CRITICAL
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-w8jh-c865-62qv: The implementation of digital signatures for JAR files in Mozilla Firefox 4
ghsa_unreviewed·2022-05-17·CVSS 7.5
CVE-2011-2993 [HIGH] GHSA-w8jh-c865-62qv: The implementation of digital signatures for JAR files in Mozilla Firefox 4
The implementation of digital signatures for JAR files in Mozilla Firefox 4.x through 5, SeaMonkey 2.x before 2.3, and possibly other products does not prevent calls from unsigned JavaScript code to signed code, which allows remote attackers to bypass the Same Origin Policy and gain privileges via a crafted web site, a different vulnerability than CVE-2008-2801.
GHSA
GHSA-gcjc-g9wr-67f2: Mozilla Firefox before 2
ghsa_unreviewed·2022-05-01
CVE-2008-2801 [HIGH] CWE-287 GHSA-gcjc-g9wr-67f2: Mozilla Firefox before 2
Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 do not properly implement JAR signing, which allows remote attackers to execute arbitrary code via (1) injection of JavaScript into documents within a JAR archive or (2) a JAR archive that uses relative URLs to JavaScript files.
Red Hat
Firefox arbitrary signed JAR code execution
vendor_redhat·2008-07-02·CVSS 7.5
CVE-2008-2801 [HIGH] Firefox arbitrary signed JAR code execution
Firefox arbitrary signed JAR code execution
Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 do not properly implement JAR signing, which allows remote attackers to execute arbitrary code via (1) injection of JavaScript into documents within a JAR archive or (2) a JAR archive that uses relative URLs to JavaScript files.
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2008-07-02·CVSS 10.0
CVE-2008-2798 [CRITICAL] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox vulnerabilities
Various flaws were discovered in the browser engine. By tricking
a user into opening a malicious web page, an attacker could cause
a denial of service via application crash, or possibly execute
arbitrary code with the privileges of the user invoking the
program. (CVE-2008-2798, CVE-2008-2799)
Several problems were discovered in the JavaScript engine. If a
user were tricked into opening a malicious web page, an attacker
could perform cross-site scripting attacks. (CVE-2008-2800)
Collin Jackson discovered various flaws in the JavaScript engine
which allowed JavaScript to be injected into signed JAR files. If
a user were tricked into opening malicious web content, an
attacker may be able to execute arbitrary code with the pri
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2008-07/msg00004.htmlhttp://rhn.redhat.com/errata/RHSA-2008-0616.htmlhttp://secunia.com/advisories/30878http://secunia.com/advisories/30898http://secunia.com/advisories/30903http://secunia.com/advisories/30911http://secunia.com/advisories/30949http://secunia.com/advisories/31005http://secunia.com/advisories/31008http://secunia.com/advisories/31021http://secunia.com/advisories/31023http://secunia.com/advisories/31069http://secunia.com/advisories/31076http://secunia.com/advisories/31183http://secunia.com/advisories/31195http://secunia.com/advisories/31377http://secunia.com/advisories/33433http://secunia.com/advisories/34501http://security.gentoo.org/glsa/glsa-200808-03.xmlhttp://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.383152http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.384911http://sunsolve.sun.com/search/document.do?assetkey=1-26-256408-1http://wiki.rpath.com/Advisories:rPSA-2008-0216http://www.debian.org/security/2008/dsa-1607http://www.debian.org/security/2008/dsa-1615http://www.debian.org/security/2009/dsa-1697http://www.mandriva.com/security/advisories?name=MDVSA-2008:136http://www.mozilla.org/projects/security/known-vulnerabilities.html#firefox2.0.0.15http://www.mozilla.org/security/announce/2008/mfsa2008-23.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0547.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0549.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0569.htmlhttp://www.securityfocus.com/archive/1/494080/100/0/threadedhttp://www.securityfocus.com/bid/30038http://www.securitytracker.com/id?1020419http://www.ubuntu.com/usn/usn-619-1http://www.vupen.com/english/advisories/2008/1993/referenceshttp://www.vupen.com/english/advisories/2009/0977https://bugzilla.mozilla.org/show_bug.cgi?id=418996https://bugzilla.mozilla.org/show_bug.cgi?id=424188https://bugzilla.mozilla.org/show_bug.cgi?id=424426https://issues.rpath.com/browse/RPL-2646https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11810https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00207.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-July/msg00288.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-July/msg00295.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-07/msg00004.htmlhttp://rhn.redhat.com/errata/RHSA-2008-0616.htmlhttp://secunia.com/advisories/30878http://secunia.com/advisories/30898http://secunia.com/advisories/30903http://secunia.com/advisories/30911http://secunia.com/advisories/30949http://secunia.com/advisories/31005http://secunia.com/advisories/31008http://secunia.com/advisories/31021http://secunia.com/advisories/31023http://secunia.com/advisories/31069http://secunia.com/advisories/31076http://secunia.com/advisories/31183http://secunia.com/advisories/31195http://secunia.com/advisories/31377http://secunia.com/advisories/33433http://secunia.com/advisories/34501http://security.gentoo.org/glsa/glsa-200808-03.xmlhttp://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.383152http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.384911http://sunsolve.sun.com/search/document.do?assetkey=1-26-256408-1http://wiki.rpath.com/Advisories:rPSA-2008-0216http://www.debian.org/security/2008/dsa-1607http://www.debian.org/security/2008/dsa-1615http://www.debian.org/security/2009/dsa-1697http://www.mandriva.com/security/advisories?name=MDVSA-2008:136http://www.mozilla.org/projects/security/known-vulnerabilities.html#firefox2.0.0.15http://www.mozilla.org/security/announce/2008/mfsa2008-23.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0547.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0549.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0569.htmlhttp://www.securityfocus.com/archive/1/494080/100/0/threadedhttp://www.securityfocus.com/bid/30038http://www.securitytracker.com/id?1020419http://www.ubuntu.com/usn/usn-619-1http://www.vupen.com/english/advisories/2008/1993/referenceshttp://www.vupen.com/english/advisories/2009/0977https://bugzilla.mozilla.org/show_bug.cgi?id=418996https://bugzilla.mozilla.org/show_bug.cgi?id=424188https://bugzilla.mozilla.org/show_bug.cgi?id=424426https://issues.rpath.com/browse/RPL-2646https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11810https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00207.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-July/msg00288.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-July/msg00295.html
2008-07-07
Published