CVE-2008-2806
published 2008-07-07CVE-2008-2806: Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 on Mac OS X allow remote attackers to bypass the Same Origin Policy and create arbitrary socket…
PriorityP334high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
2.55%
83.4th percentile
Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 on Mac OS X allow remote attackers to bypass the Same Origin Policy and create arbitrary socket connections via a crafted Java applet, related to the Java Embedding Plugin (JEP) and Java LiveConnect.
Affected
33 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_ubuntu10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3x7r-r5xh-2v32: Mozilla Firefox before 2
ghsa_unreviewed·2022-05-01
CVE-2008-2806 [HIGH] CWE-20 GHSA-3x7r-r5xh-2v32: Mozilla Firefox before 2
Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 on Mac OS X allow remote attackers to bypass the Same Origin Policy and create arbitrary socket connections via a crafted Java applet, related to the Java Embedding Plugin (JEP) and Java LiveConnect.
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2008-07-02·CVSS 10.0
CVE-2008-2798 [CRITICAL] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox vulnerabilities
Various flaws were discovered in the browser engine. By tricking
a user into opening a malicious web page, an attacker could cause
a denial of service via application crash, or possibly execute
arbitrary code with the privileges of the user invoking the
program. (CVE-2008-2798, CVE-2008-2799)
Several problems were discovered in the JavaScript engine. If a
user were tricked into opening a malicious web page, an attacker
could perform cross-site scripting attacks. (CVE-2008-2800)
Collin Jackson discovered various flaws in the JavaScript engine
which allowed JavaScript to be injected into signed JAR files. If
a user were tricked into opening malicious web content, an
attacker may be able to execute arbitrary code with the pri
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://lists.opensuse.org/opensuse-security-announce/2008-07/msg00004.htmlhttp://secunia.com/advisories/30898http://secunia.com/advisories/30911http://secunia.com/advisories/31005http://secunia.com/advisories/31008http://secunia.com/advisories/31021http://secunia.com/advisories/31023http://secunia.com/advisories/31076http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.383152http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.384911http://wiki.rpath.com/Advisories:rPSA-2008-0216http://www.mozilla.org/projects/security/known-vulnerabilities.html#firefox2.0.0.15http://www.mozilla.org/security/announce/2008/mfsa2008-28.htmlhttp://www.securityfocus.com/archive/1/494080/100/0/threadedhttp://www.securityfocus.com/bid/30038http://www.securitytracker.com/id?1020419http://www.ubuntu.com/usn/usn-619-1http://www.vupen.com/english/advisories/2008/1993/referenceshttps://bugzilla.mozilla.org/show_bug.cgi?id=408329https://issues.rpath.com/browse/RPL-2646https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00288.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-July/msg00295.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-07/msg00004.htmlhttp://secunia.com/advisories/30898http://secunia.com/advisories/30911http://secunia.com/advisories/31005http://secunia.com/advisories/31008http://secunia.com/advisories/31021http://secunia.com/advisories/31023http://secunia.com/advisories/31076http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.383152http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.384911http://wiki.rpath.com/Advisories:rPSA-2008-0216http://www.mozilla.org/projects/security/known-vulnerabilities.html#firefox2.0.0.15http://www.mozilla.org/security/announce/2008/mfsa2008-28.htmlhttp://www.securityfocus.com/archive/1/494080/100/0/threadedhttp://www.securityfocus.com/bid/30038http://www.securitytracker.com/id?1020419http://www.ubuntu.com/usn/usn-619-1http://www.vupen.com/english/advisories/2008/1993/referenceshttps://bugzilla.mozilla.org/show_bug.cgi?id=408329https://issues.rpath.com/browse/RPL-2646https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00288.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-July/msg00295.html
2008-07-07
Published