CVE-2008-5015
published 2008-11-13CVE-2008-5015: Mozilla Firefox 3.x before 3.0.4 assigns chrome privileges to a file: URI when it is accessed in the same tab from a chrome or privileged about: page, which…
PriorityP423medium5.1CVSS 2.0
AVNACHAuNCPIPAP
EPSS
2.17%
80.5th percentile
Mozilla Firefox 3.x before 3.0.4 assigns chrome privileges to a file: URI when it is accessed in the same tab from a chrome or privileged about: page, which makes it easier for user-assisted attackers to execute arbitrary JavaScript with chrome privileges via malicious code in a file that has already been saved on the local system.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 3.0.3 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
CVSS provenance
nvdv2.05.1MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:P
vendor_redhat5.1MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Firefox and xulrunner vulnerabilities
vendor_ubuntu·2008-11-17·CVSS 4.3
CVE-2008-4582 [MEDIUM] Firefox and xulrunner vulnerabilities
Title: Firefox and xulrunner vulnerabilities
Summary: Firefox and xulrunner vulnerabilities
Liu Die Yu discovered an information disclosure vulnerability in Firefox
when using saved .url shortcut files. If a user were tricked into
downloading a crafted .url file and a crafted HTML file, an attacker
could steal information from the user's cache. (CVE-2008-4582)
Georgi Guninski, Michal Zalewsk and Chris Evans discovered that the
same-origin check in Firefox could be bypassed. If a user were tricked
into opening a malicious website, an attacker could obtain private
information from data stored in the images, or discover information
about software on the user's computer. This issue only affects Firefox 2.
(CVE-2008-5012)
It was discovered that Firefox did not properly check if the Flash
mo
Red Hat
file: URIs inherit chrome privileges
vendor_redhat·2008-11-12·CVSS 5.1
CVE-2008-5015 [MEDIUM] file: URIs inherit chrome privileges
file: URIs inherit chrome privileges
Mozilla Firefox 3.x before 3.0.4 assigns chrome privileges to a file: URI when it is accessed in the same tab from a chrome or privileged about: page, which makes it easier for user-assisted attackers to execute arbitrary JavaScript with chrome privileges via malicious code in a file that has already been saved on the local system.
Red Hat
opensc: incorrect initialization of Siemens CardOS M4 smart cards
vendor_redhat·2008-07-31·CVSS 4.9
CVE-2008-2235 [MEDIUM] opensc: incorrect initialization of Siemens CardOS M4 smart cards
opensc: incorrect initialization of Siemens CardOS M4 smart cards
OpenSC before 0.11.5 uses weak permissions (ADMIN file control information of 00) for the 5015 directory on smart cards and USB crypto tokens running Siemens CardOS M4, which allows physically proximate attackers to change the PIN.
GHSA
GHSA-w7p9-j7cw-wfpm: Mozilla Firefox 3
ghsa_unreviewed·2022-05-17
CVE-2008-5015 [MEDIUM] CWE-94 GHSA-w7p9-j7cw-wfpm: Mozilla Firefox 3
Mozilla Firefox 3.x before 3.0.4 assigns chrome privileges to a file: URI when it is accessed in the same tab from a chrome or privileged about: page, which makes it easier for user-assisted attackers to execute arbitrary JavaScript with chrome privileges via malicious code in a file that has already been saved on the local system.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00004.htmlhttp://secunia.com/advisories/32695http://secunia.com/advisories/32713http://secunia.com/advisories/32721http://secunia.com/advisories/32778http://secunia.com/advisories/34501http://sunsolve.sun.com/search/document.do?assetkey=1-26-256408-1http://ubuntu.com/usn/usn-667-1http://www.mandriva.com/security/advisories?name=MDVSA-2008:230http://www.mozilla.org/security/announce/2008/mfsa2008-51.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0978.htmlhttp://www.securityfocus.com/bid/32281http://www.securitytracker.com/id?1021191http://www.us-cert.gov/cas/techalerts/TA08-319A.htmlhttp://www.vupen.com/english/advisories/2008/3146http://www.vupen.com/english/advisories/2009/0977https://bugzilla.mozilla.org/show_bug.cgi?id=447579https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11063https://www.redhat.com/archives/fedora-package-announce/2008-November/msg00385.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-11/msg00004.htmlhttp://secunia.com/advisories/32695http://secunia.com/advisories/32713http://secunia.com/advisories/32721http://secunia.com/advisories/32778http://secunia.com/advisories/34501http://sunsolve.sun.com/search/document.do?assetkey=1-26-256408-1http://ubuntu.com/usn/usn-667-1http://www.mandriva.com/security/advisories?name=MDVSA-2008:230http://www.mozilla.org/security/announce/2008/mfsa2008-51.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0978.htmlhttp://www.securityfocus.com/bid/32281http://www.securitytracker.com/id?1021191http://www.us-cert.gov/cas/techalerts/TA08-319A.htmlhttp://www.vupen.com/english/advisories/2008/3146http://www.vupen.com/english/advisories/2009/0977https://bugzilla.mozilla.org/show_bug.cgi?id=447579https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11063https://www.redhat.com/archives/fedora-package-announce/2008-November/msg00385.html
2008-11-13
Published