CVE-2008-4060Mozilla Firefox vulnerability

CWE-2649 documents6 sources
Severity
7.5HIGHNVD
EPSS
2.0%
top 16.22%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 24
Latest updateMay 2

Description

Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allow remote attackers to create documents that lack script-handling objects, and execute arbitrary code with chrome privileges, via vectors related to (1) the document.loadBindingDocument function and (2) XSLT.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages3 packages

NVDmozilla/firefox2.0.0.16+49
NVDmozilla/seamonkey1.1.11+14
NVDmozilla/thunderbird2.0.0.16+58

Patches

🔴Vulnerability Details

2
GHSA
GHSA-vgvw-jj2g-rp9v: Mozilla Firefox before 22022-05-02
CVEList
CVE-2008-4060: Mozilla Firefox before 22008-09-24

📋Vendor Advisories

5
Ubuntu
Thunderbird vulnerabilities2008-09-26
Ubuntu
Firefox and xulrunner regression2008-09-25
Ubuntu
Firefox vulnerabilities2008-09-24
Ubuntu
Firefox and xulrunner vulnerabilities2008-09-24
Red Hat
Mozilla privilege escalation via XPCnativeWrapper pollution2008-09-23

💬Community

1
Bugzilla
CVE-2008-4060 Mozilla privilege escalation via XPCnativeWrapper pollution2008-09-22
CVE-2008-4060 — Mozilla Firefox vulnerability | cvebase