CVE-2008-4069
published 2008-09-24CVE-2008-4069: The XBM decoder in Mozilla Firefox before 2.0.0.17 and SeaMonkey before 1.1.12 allows remote attackers to read uninitialized memory, and possibly obtain…
PriorityP421medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
1.66%
74.1th percentile
The XBM decoder in Mozilla Firefox before 2.0.0.17 and SeaMonkey before 1.1.12 allows remote attackers to read uninitialized memory, and possibly obtain sensitive information in opportunistic circumstances, via a crafted XBM image file.
Affected
63 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 2.0.0.16 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_ubuntu10.0CRITICAL
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Firefox and xulrunner regression
vendor_ubuntu·2008-09-25·CVSS 10.0
[CRITICAL] Firefox and xulrunner regression
Title: Firefox and xulrunner regression
Summary: Firefox and xulrunner regression
USN-645-1 fixed vulnerabilities in Firefox and xulrunner. The upstream
patches introduced a regression in the saved password handling. While
password data was not lost, if a user had saved any passwords with
non-ASCII characters, Firefox could not access the password database.
This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Justin Schuh, Tom Cross and Peter Williams discovered errors in the
Firefox URL parsing routines. If a user were tricked into opening a
crafted hyperlink, an attacker could overflow a stack buffer and
execute arbitrary code. (CVE-2008-0016)
It was discovered that the same-origin check in Firefox could be
bypassed. If a user were tricked i
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2008-09-24·CVSS 10.0
CVE-2008-0016 [CRITICAL] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox vulnerabilities
USN-645-1 fixed vulnerabilities in Firefox and xulrunner for Ubuntu
7.04, 7.10 and 8.04 LTS. This provides the corresponding update for
Ubuntu 6.06 LTS.
Original advisory details:
Justin Schuh, Tom Cross and Peter Williams discovered errors in the
Firefox URL parsing routines. If a user were tricked into opening a
crafted hyperlink, an attacker could overflow a stack buffer and
execute arbitrary code. (CVE-2008-0016)
It was discovered that the same-origin check in Firefox could be
bypassed. If a user were tricked into opening a malicious website,
an attacker may be able to execute JavaScript in the context of a
different website. (CVE-2008-3835)
Several problems were discovered in the JavaScript engine. This
could allow
Ubuntu
Firefox and xulrunner vulnerabilities
vendor_ubuntu·2008-09-24·CVSS 10.0
CVE-2008-0016 [CRITICAL] Firefox and xulrunner vulnerabilities
Title: Firefox and xulrunner vulnerabilities
Summary: Firefox and xulrunner vulnerabilities
Justin Schuh, Tom Cross and Peter Williams discovered errors in the
Firefox URL parsing routines. If a user were tricked into opening a
crafted hyperlink, an attacker could overflow a stack buffer and
execute arbitrary code. (CVE-2008-0016)
It was discovered that the same-origin check in Firefox could be
bypassed. If a user were tricked into opening a malicious website,
an attacker may be able to execute JavaScript in the context of a
different website. (CVE-2008-3835)
Several problems were discovered in the JavaScript engine. This
could allow an attacker to execute scripts from page content with
chrome privileges. (CVE-2008-3836)
Paul Nickerson discovered Firefox did not properly process mouse
Red Hat
Mozilla XBM decoder information disclosure
vendor_redhat·2008-09-23·CVSS 5.0
CVE-2008-4069 [MEDIUM] Mozilla XBM decoder information disclosure
Mozilla XBM decoder information disclosure
The XBM decoder in Mozilla Firefox before 2.0.0.17 and SeaMonkey before 1.1.12 allows remote attackers to read uninitialized memory, and possibly obtain sensitive information in opportunistic circumstances, via a crafted XBM image file.
GHSA
GHSA-j7hh-6fv3-pr3p: The XBM decoder in Mozilla Firefox before 2
ghsa_unreviewed·2022-05-02
CVE-2008-4069 [MEDIUM] CWE-200 GHSA-j7hh-6fv3-pr3p: The XBM decoder in Mozilla Firefox before 2
The XBM decoder in Mozilla Firefox before 2.0.0.17 and SeaMonkey before 1.1.12 allows remote attackers to read uninitialized memory, and possibly obtain sensitive information in opportunistic circumstances, via a crafted XBM image file.
No detection rules found.
No public exploits indexed.
http://download.novell.com/Download?buildid=WZXONb-tqBw~http://lists.opensuse.org/opensuse-security-announce/2008-10/msg00005.htmlhttp://secunia.com/advisories/31984http://secunia.com/advisories/31985http://secunia.com/advisories/32010http://secunia.com/advisories/32012http://secunia.com/advisories/32042http://secunia.com/advisories/32044http://secunia.com/advisories/32144http://secunia.com/advisories/32185http://secunia.com/advisories/32196http://secunia.com/advisories/32845http://secunia.com/advisories/33433http://secunia.com/advisories/34501http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.379422http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.405232http://sunsolve.sun.com/search/document.do?assetkey=1-26-256408-1http://www.blackhat.com/presentations/bh-usa-08/Hoffman/Hoffman-BH2008-CircumventingJavaScript.ppthttp://www.debian.org/security/2008/dsa-1649http://www.debian.org/security/2008/dsa-1669http://www.debian.org/security/2009/dsa-1697http://www.mandriva.com/security/advisories?name=MDVSA-2008:205http://www.mozilla.org/security/announce/2008/mfsa2008-45.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0882.htmlhttp://www.securityfocus.com/bid/31346http://www.securitytracker.com/id?1020923http://www.ubuntu.com/usn/usn-645-1http://www.ubuntu.com/usn/usn-645-2http://www.vupen.com/english/advisories/2008/2661http://www.vupen.com/english/advisories/2009/0977https://bugzilla.mozilla.org/show_bug.cgi?id=449703https://exchange.xforce.ibmcloud.com/vulnerabilities/45361https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11000https://www.redhat.com/archives/fedora-package-announce/2008-September/msg01384.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-September/msg01403.htmlhttp://download.novell.com/Download?buildid=WZXONb-tqBw~http://lists.opensuse.org/opensuse-security-announce/2008-10/msg00005.htmlhttp://secunia.com/advisories/31984http://secunia.com/advisories/31985http://secunia.com/advisories/32010http://secunia.com/advisories/32012http://secunia.com/advisories/32042http://secunia.com/advisories/32044http://secunia.com/advisories/32144http://secunia.com/advisories/32185http://secunia.com/advisories/32196http://secunia.com/advisories/32845http://secunia.com/advisories/33433http://secunia.com/advisories/34501http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.379422http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.405232http://sunsolve.sun.com/search/document.do?assetkey=1-26-256408-1http://www.blackhat.com/presentations/bh-usa-08/Hoffman/Hoffman-BH2008-CircumventingJavaScript.ppthttp://www.debian.org/security/2008/dsa-1649http://www.debian.org/security/2008/dsa-1669http://www.debian.org/security/2009/dsa-1697http://www.mandriva.com/security/advisories?name=MDVSA-2008:205http://www.mozilla.org/security/announce/2008/mfsa2008-45.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0882.htmlhttp://www.securityfocus.com/bid/31346http://www.securitytracker.com/id?1020923http://www.ubuntu.com/usn/usn-645-1http://www.ubuntu.com/usn/usn-645-2http://www.vupen.com/english/advisories/2008/2661http://www.vupen.com/english/advisories/2009/0977https://bugzilla.mozilla.org/show_bug.cgi?id=449703https://exchange.xforce.ibmcloud.com/vulnerabilities/45361https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11000https://www.redhat.com/archives/fedora-package-announce/2008-September/msg01384.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-September/msg01403.html
2008-09-24
Published