CVE-2008-5012
published 2008-11-13CVE-2008-5012: Mozilla Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 do not properly change the source URI when processing a…
PriorityP426medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
2.04%
79.0th percentile
Mozilla Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 do not properly change the source URI when processing a canvas element and an HTTP redirect, which allows remote attackers to bypass the same origin policy and access arbitrary images that are not directly accessible to the attacker. NOTE: this issue can be leveraged to enumerate software on the client by performing redirections related to moz-icon.
Affected
129 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 2.0.0.17 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat5.0MEDIUM
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2008-11-26·CVSS 5.0
CVE-2008-5012 [MEDIUM] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Thunderbird vulnerabilities
Georgi Guninski, Michal Zalewsk and Chris Evans discovered that the same-origin
check in Thunderbird could be bypassed. If a user were tricked into opening a
malicious website, an attacker could obtain private information from data
stored in the images, or discover information about software on the user's
computer. (CVE-2008-5012)
Jesse Ruderman discovered that Thunderbird did not properly guard locks on
non-native objects. If a user had JavaScript enabled and were tricked into
opening malicious web content, an attacker could cause a browser crash and
possibly execute arbitrary code with user privileges. (CVE-2008-5014)
Several problems were discovered in the browser, layout and JavaScript engines.
If a user had Ja
Ubuntu
Firefox and xulrunner vulnerabilities
vendor_ubuntu·2008-11-17·CVSS 4.3
CVE-2008-4582 [MEDIUM] Firefox and xulrunner vulnerabilities
Title: Firefox and xulrunner vulnerabilities
Summary: Firefox and xulrunner vulnerabilities
Liu Die Yu discovered an information disclosure vulnerability in Firefox
when using saved .url shortcut files. If a user were tricked into
downloading a crafted .url file and a crafted HTML file, an attacker
could steal information from the user's cache. (CVE-2008-4582)
Georgi Guninski, Michal Zalewsk and Chris Evans discovered that the
same-origin check in Firefox could be bypassed. If a user were tricked
into opening a malicious website, an attacker could obtain private
information from data stored in the images, or discover information
about software on the user's computer. This issue only affects Firefox 2.
(CVE-2008-5012)
It was discovered that Firefox did not properly check if the Flash
mo
Red Hat
Mozilla Image stealing via canvas and HTTP redirect
vendor_redhat·2008-11-12·CVSS 5.0
CVE-2008-5012 [MEDIUM] Mozilla Image stealing via canvas and HTTP redirect
Mozilla Image stealing via canvas and HTTP redirect
Mozilla Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 do not properly change the source URI when processing a canvas element and an HTTP redirect, which allows remote attackers to bypass the same origin policy and access arbitrary images that are not directly accessible to the attacker. NOTE: this issue can be leveraged to enumerate software on the client by performing redirections related to moz-icon.
GHSA
GHSA-hfvm-r385-4pvq: Mozilla Firefox 2
ghsa_unreviewed·2022-05-17
CVE-2008-5012 [MEDIUM] CWE-200 GHSA-hfvm-r385-4pvq: Mozilla Firefox 2
Mozilla Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 do not properly change the source URI when processing a canvas element and an HTTP redirect, which allows remote attackers to bypass the same origin policy and access arbitrary images that are not directly accessible to the attacker. NOTE: this issue can be leveraged to enumerate software on the client by performing redirections related to moz-icon.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00004.htmlhttp://scary.beasts.org/security/CESA-2008-009.htmlhttp://scarybeastsecurity.blogspot.com/2008/11/firefox-cross-domain-image-theft-and.htmlhttp://secunia.com/advisories/32684http://secunia.com/advisories/32693http://secunia.com/advisories/32694http://secunia.com/advisories/32714http://secunia.com/advisories/32715http://secunia.com/advisories/32778http://secunia.com/advisories/32798http://secunia.com/advisories/32845http://secunia.com/advisories/32853http://secunia.com/advisories/33433http://secunia.com/advisories/33434http://secunia.com/advisories/34501http://sunsolve.sun.com/search/document.do?assetkey=1-26-256408-1http://ubuntu.com/usn/usn-667-1http://www.debian.org/security/2008/dsa-1669http://www.debian.org/security/2008/dsa-1671http://www.debian.org/security/2009/dsa-1696http://www.debian.org/security/2009/dsa-1697http://www.mandriva.com/security/advisories?name=MDVSA-2008:228http://www.mandriva.com/security/advisories?name=MDVSA-2008:235http://www.mozilla.org/security/announce/2008/mfsa2008-48.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0976.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0977.htmlhttp://www.securityfocus.com/archive/1/498468http://www.securityfocus.com/bid/32281http://www.securityfocus.com/bid/32351http://www.securitytracker.com/id?1021187http://www.us-cert.gov/cas/techalerts/TA08-319A.htmlhttp://www.vupen.com/english/advisories/2008/3146http://www.vupen.com/english/advisories/2009/0977https://bugzilla.mozilla.org/show_bug.cgi?id=355126https://bugzilla.mozilla.org/show_bug.cgi?id=451619https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10750https://www.redhat.com/archives/fedora-package-announce/2008-November/msg00366.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-11/msg00004.htmlhttp://scary.beasts.org/security/CESA-2008-009.htmlhttp://scarybeastsecurity.blogspot.com/2008/11/firefox-cross-domain-image-theft-and.htmlhttp://secunia.com/advisories/32684http://secunia.com/advisories/32693http://secunia.com/advisories/32694http://secunia.com/advisories/32714http://secunia.com/advisories/32715http://secunia.com/advisories/32778http://secunia.com/advisories/32798http://secunia.com/advisories/32845http://secunia.com/advisories/32853http://secunia.com/advisories/33433http://secunia.com/advisories/33434http://secunia.com/advisories/34501http://sunsolve.sun.com/search/document.do?assetkey=1-26-256408-1http://ubuntu.com/usn/usn-667-1http://www.debian.org/security/2008/dsa-1669http://www.debian.org/security/2008/dsa-1671http://www.debian.org/security/2009/dsa-1696http://www.debian.org/security/2009/dsa-1697http://www.mandriva.com/security/advisories?name=MDVSA-2008:228http://www.mandriva.com/security/advisories?name=MDVSA-2008:235http://www.mozilla.org/security/announce/2008/mfsa2008-48.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0976.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0977.htmlhttp://www.securityfocus.com/archive/1/498468http://www.securityfocus.com/bid/32281http://www.securityfocus.com/bid/32351http://www.securitytracker.com/id?1021187http://www.us-cert.gov/cas/techalerts/TA08-319A.htmlhttp://www.vupen.com/english/advisories/2008/3146http://www.vupen.com/english/advisories/2009/0977https://bugzilla.mozilla.org/show_bug.cgi?id=355126https://bugzilla.mozilla.org/show_bug.cgi?id=451619https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10750https://www.redhat.com/archives/fedora-package-announce/2008-November/msg00366.html
2008-11-13
Published