CVE-2008-4059Mozilla Firefox vulnerability

CWE-2648 documents5 sources
Severity
7.5HIGHNVD
EPSS
1.7%
top 17.57%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 24
Latest updateMay 2

Description

The XPConnect component in Mozilla Firefox before 2.0.0.17 allows remote attackers to "pollute XPCNativeWrappers" and execute arbitrary code with chrome privileges via vectors related to a SCRIPT element.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages1 packages

NVDmozilla/firefox2.0.0.17+56

Patches

🔴Vulnerability Details

1
GHSA
GHSA-r373-c84r-h3c6: The XPConnect component in Mozilla Firefox before 22022-05-02

📋Vendor Advisories

5
Ubuntu
Thunderbird vulnerabilities2008-09-26
Ubuntu
Firefox and xulrunner regression2008-09-25
Ubuntu
Firefox vulnerabilities2008-09-24
Ubuntu
Firefox and xulrunner vulnerabilities2008-09-24
Red Hat
Mozilla privilege escalation via XPCnativeWrapper pollution2008-09-23

💬Community

1
Bugzilla
CVE-2008-4059 Mozilla privilege escalation via XPCnativeWrapper pollution2008-09-22