CVE-2008-5019Cross-site Scripting in Mozilla Firefox

Severity
4.3MEDIUMNVD
EPSS
12.8%
top 5.95%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 13
Latest updateMay 14

Description

The session restore feature in Mozilla Firefox 3.x before 3.0.4 and 2.x before 2.0.0.18 allows remote attackers to violate the same origin policy to conduct cross-site scripting (XSS) attacks and execute arbitrary JavaScript with chrome privileges via unknown vectors.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages1 packages

NVDmozilla/firefox2.02.0.0.18+1

Also affects: Debian Linux 4.0, Ubuntu Linux 6.06, 7.10, 8.04, 8.10

🔴Vulnerability Details

1
GHSA
GHSA-w542-59hv-5363: The session restore feature in Mozilla Firefox 32022-05-14

📋Vendor Advisories

2
Ubuntu
Firefox and xulrunner vulnerabilities2008-11-17
Red Hat
Mozilla XSS via session restore2008-11-12

💬Community

1
Bugzilla
CVE-2008-5019 Mozilla XSS via session restore2008-11-10