CVE-2008-3836Cross-site Scripting in Mozilla Firefox

Severity
7.5HIGHNVD
EPSS
2.9%
top 13.54%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 24
Latest updateMay 17

Description

feedWriter in Mozilla Firefox before 2.0.0.17 allows remote attackers to execute scripts with chrome privileges via vectors related to feed preview and the (1) elem.doCommand, (2) elem.dispatchEvent, (3) _setTitleText, (4) _setTitleImage, and (5) _initSubscriptionUI functions.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages1 packages

NVDmozilla/firefox2.0.0.18+58

Patches

🔴Vulnerability Details

2
GHSA
GHSA-hph5-qh8m-x8v8: Mozilla Firefox 22022-05-17
GHSA
GHSA-v3vw-x43v-2399: feedWriter in Mozilla Firefox before 22022-05-02

📋Vendor Advisories

5
Red Hat
Firefox 2 XSS attack vectors in feed preview2008-12-16
Ubuntu
Firefox and xulrunner regression2008-09-25
Ubuntu
Firefox vulnerabilities2008-09-24
Ubuntu
Firefox and xulrunner vulnerabilities2008-09-24
Red Hat
mozilla: Privilege escalation using feed preview page and XSS flaw2008-09-23

💬Community

1
Bugzilla
CVE-2008-3836 mozilla: Privilege escalation using feed preview page and XSS flaw2008-09-22