CVE-2008-3835
published 2008-09-24CVE-2008-3835: The nsXMLDocument::OnChannelRedirect function in Mozilla Firefox before 2.0.0.17, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows remote…
PriorityP434high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
2.14%
80.0th percentile
The nsXMLDocument::OnChannelRedirect function in Mozilla Firefox before 2.0.0.17, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows remote attackers to bypass the Same Origin Policy and execute arbitrary JavaScript code via unknown vectors.
Affected
122 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 2.0.0.16 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_ubuntu10.0CRITICAL
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-359f-mc8p-j8g3: The nsXMLDocument::OnChannelRedirect function in Mozilla Firefox before 2
ghsa_unreviewed·2022-05-02
CVE-2008-3835 [HIGH] GHSA-359f-mc8p-j8g3: The nsXMLDocument::OnChannelRedirect function in Mozilla Firefox before 2
The nsXMLDocument::OnChannelRedirect function in Mozilla Firefox before 2.0.0.17, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows remote attackers to bypass the Same Origin Policy and execute arbitrary JavaScript code via unknown vectors.
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2008-09-26·CVSS 7.5
CVE-2008-4067 [HIGH] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Thunderbird vulnerabilities
It was discovered that the same-origin check in Thunderbird could
be bypassed. If a user had JavaScript enabled and were tricked into
opening a malicious website, an attacker may be able to execute
JavaScript in the context of a different website. (CVE-2008-3835)
Several problems were discovered in the browser engine of
Thunderbird. If a user had JavaScript enabled, this could allow an
attacker to execute code with chrome privileges. (CVE-2008-4058,
CVE-2008-4059, CVE-2008-4060)
Drew Yao, David Maciejak and other Mozilla developers found several
problems in the browser engine of Thunderbird. If a user had
JavaScript enabled and were tricked into opening a malicious web
page, an attacker could cause a denial of serv
Ubuntu
Firefox and xulrunner regression
vendor_ubuntu·2008-09-25·CVSS 10.0
[CRITICAL] Firefox and xulrunner regression
Title: Firefox and xulrunner regression
Summary: Firefox and xulrunner regression
USN-645-1 fixed vulnerabilities in Firefox and xulrunner. The upstream
patches introduced a regression in the saved password handling. While
password data was not lost, if a user had saved any passwords with
non-ASCII characters, Firefox could not access the password database.
This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Justin Schuh, Tom Cross and Peter Williams discovered errors in the
Firefox URL parsing routines. If a user were tricked into opening a
crafted hyperlink, an attacker could overflow a stack buffer and
execute arbitrary code. (CVE-2008-0016)
It was discovered that the same-origin check in Firefox could be
bypassed. If a user were tricked i
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2008-09-24·CVSS 10.0
CVE-2008-0016 [CRITICAL] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox vulnerabilities
USN-645-1 fixed vulnerabilities in Firefox and xulrunner for Ubuntu
7.04, 7.10 and 8.04 LTS. This provides the corresponding update for
Ubuntu 6.06 LTS.
Original advisory details:
Justin Schuh, Tom Cross and Peter Williams discovered errors in the
Firefox URL parsing routines. If a user were tricked into opening a
crafted hyperlink, an attacker could overflow a stack buffer and
execute arbitrary code. (CVE-2008-0016)
It was discovered that the same-origin check in Firefox could be
bypassed. If a user were tricked into opening a malicious website,
an attacker may be able to execute JavaScript in the context of a
different website. (CVE-2008-3835)
Several problems were discovered in the JavaScript engine. This
could allow
Ubuntu
Firefox and xulrunner vulnerabilities
vendor_ubuntu·2008-09-24·CVSS 10.0
CVE-2008-0016 [CRITICAL] Firefox and xulrunner vulnerabilities
Title: Firefox and xulrunner vulnerabilities
Summary: Firefox and xulrunner vulnerabilities
Justin Schuh, Tom Cross and Peter Williams discovered errors in the
Firefox URL parsing routines. If a user were tricked into opening a
crafted hyperlink, an attacker could overflow a stack buffer and
execute arbitrary code. (CVE-2008-0016)
It was discovered that the same-origin check in Firefox could be
bypassed. If a user were tricked into opening a malicious website,
an attacker may be able to execute JavaScript in the context of a
different website. (CVE-2008-3835)
Several problems were discovered in the JavaScript engine. This
could allow an attacker to execute scripts from page content with
chrome privileges. (CVE-2008-3836)
Paul Nickerson discovered Firefox did not properly process mouse
Red Hat
mozilla: nsXMLDocument:: OnChannelRedirect() same-origin violation
vendor_redhat·2008-09-23·CVSS 7.5
CVE-2008-3835 [HIGH] mozilla: nsXMLDocument:: OnChannelRedirect() same-origin violation
mozilla: nsXMLDocument:: OnChannelRedirect() same-origin violation
The nsXMLDocument::OnChannelRedirect function in Mozilla Firefox before 2.0.0.17, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows remote attackers to bypass the Same Origin Policy and execute arbitrary JavaScript code via unknown vectors.
No detection rules found.
No public exploits indexed.
http://download.novell.com/Download?buildid=WZXONb-tqBw~http://lists.opensuse.org/opensuse-security-announce/2008-10/msg00005.htmlhttp://secunia.com/advisories/31984http://secunia.com/advisories/31985http://secunia.com/advisories/32007http://secunia.com/advisories/32010http://secunia.com/advisories/32012http://secunia.com/advisories/32025http://secunia.com/advisories/32042http://secunia.com/advisories/32044http://secunia.com/advisories/32082http://secunia.com/advisories/32092http://secunia.com/advisories/32144http://secunia.com/advisories/32185http://secunia.com/advisories/32196http://secunia.com/advisories/32845http://secunia.com/advisories/33433http://secunia.com/advisories/33434http://secunia.com/advisories/34501http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.379422http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.405232http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.412123http://sunsolve.sun.com/search/document.do?assetkey=1-26-256408-1http://www.debian.org/security/2008/dsa-1649http://www.debian.org/security/2008/dsa-1669http://www.debian.org/security/2009/dsa-1696http://www.debian.org/security/2009/dsa-1697http://www.mandriva.com/security/advisories?name=MDVSA-2008:205http://www.mandriva.com/security/advisories?name=MDVSA-2008:206http://www.mozilla.org/security/announce/2008/mfsa2008-38.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0882.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0908.htmlhttp://www.securityfocus.com/bid/31346http://www.securitytracker.com/id?1020919http://www.ubuntu.com/usn/usn-645-1http://www.ubuntu.com/usn/usn-645-2http://www.ubuntu.com/usn/usn-647-1http://www.vupen.com/english/advisories/2008/2661http://www.vupen.com/english/advisories/2009/0977https://bugzilla.mozilla.org/show_bug.cgi?id=439034https://exchange.xforce.ibmcloud.com/vulnerabilities/45347https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9643https://www.redhat.com/archives/fedora-package-announce/2008-September/msg01384.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-September/msg01403.htmlhttp://download.novell.com/Download?buildid=WZXONb-tqBw~http://lists.opensuse.org/opensuse-security-announce/2008-10/msg00005.htmlhttp://secunia.com/advisories/31984http://secunia.com/advisories/31985http://secunia.com/advisories/32007http://secunia.com/advisories/32010http://secunia.com/advisories/32012http://secunia.com/advisories/32025http://secunia.com/advisories/32042http://secunia.com/advisories/32044http://secunia.com/advisories/32082http://secunia.com/advisories/32092http://secunia.com/advisories/32144http://secunia.com/advisories/32185http://secunia.com/advisories/32196http://secunia.com/advisories/32845http://secunia.com/advisories/33433http://secunia.com/advisories/33434http://secunia.com/advisories/34501http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.379422http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.405232http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.412123http://sunsolve.sun.com/search/document.do?assetkey=1-26-256408-1http://www.debian.org/security/2008/dsa-1649http://www.debian.org/security/2008/dsa-1669http://www.debian.org/security/2009/dsa-1696http://www.debian.org/security/2009/dsa-1697http://www.mandriva.com/security/advisories?name=MDVSA-2008:205http://www.mandriva.com/security/advisories?name=MDVSA-2008:206http://www.mozilla.org/security/announce/2008/mfsa2008-38.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0882.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0908.htmlhttp://www.securityfocus.com/bid/31346http://www.securitytracker.com/id?1020919http://www.ubuntu.com/usn/usn-645-1http://www.ubuntu.com/usn/usn-645-2http://www.ubuntu.com/usn/usn-647-1http://www.vupen.com/english/advisories/2008/2661http://www.vupen.com/english/advisories/2009/0977https://bugzilla.mozilla.org/show_bug.cgi?id=439034https://exchange.xforce.ibmcloud.com/vulnerabilities/45347https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9643https://www.redhat.com/archives/fedora-package-announce/2008-September/msg01384.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-September/msg01403.html
2008-09-24
Published