CVE-2008-3198
published 2008-07-17CVE-2008-3198: Mozilla Firefox 3.x before 3.0.1 allows remote attackers to inject arbitrary web script into a chrome document via unspecified vectors, as demonstrated by…
PriorityP432high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
2.96%
85.8th percentile
Mozilla Firefox 3.x before 3.0.1 allows remote attackers to inject arbitrary web script into a chrome document via unspecified vectors, as demonstrated by injection into a XUL error page. NOTE: this can be leveraged to execute arbitrary code using CVE-2008-2933.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat2.6LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jrjj-g3cm-58m8: Mozilla Firefox 3
ghsa_unreviewed·2022-05-01·CVSS 2.6
CVE-2008-3198 [LOW] CWE-94 GHSA-jrjj-g3cm-58m8: Mozilla Firefox 3
Mozilla Firefox 3.x before 3.0.1 allows remote attackers to inject arbitrary web script into a chrome document via unspecified vectors, as demonstrated by injection into a XUL error page. NOTE: this can be leveraged to execute arbitrary code using CVE-2008-2933.
Red Hat
security flaw
vendor_redhat·2008-07-15·CVSS 2.6
CVE-2008-3198 [LOW] security flaw
security flaw
Mozilla Firefox 3.x before 3.0.1 allows remote attackers to inject arbitrary web script into a chrome document via unspecified vectors, as demonstrated by injection into a XUL error page. NOTE: this can be leveraged to execute arbitrary code using CVE-2008-2933.
No detection rules found.
No public exploits indexed.
http://www.mozilla.org/security/announce/2008/mfsa2008-35.htmlhttp://www.securityfocus.com/bid/30244https://bugzilla.mozilla.org/show_bug.cgi?id=441169https://exchange.xforce.ibmcloud.com/vulnerabilities/44199http://www.mozilla.org/security/announce/2008/mfsa2008-35.htmlhttp://www.securityfocus.com/bid/30244https://bugzilla.mozilla.org/show_bug.cgi?id=441169https://exchange.xforce.ibmcloud.com/vulnerabilities/44199
2008-07-17
Published