CVE-2008-5023
published 2008-11-13CVE-2008-5023: Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to bypass the protection mechanism for codebase…
PriorityP339high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
3.26%
87.0th percentile
Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to bypass the protection mechanism for codebase principals and execute arbitrary script via the -moz-binding CSS property in a signed JAR file.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| mozilla | firefox | >= 2.0 < 2.0.0.18 | 2.0.0.18 |
| mozilla | firefox | >= 3.0 < 3.0.4 | 3.0.4 |
| mozilla | seamonkey | >= 1.0 < 1.1.13 | 1.1.13 |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat7.5HIGH
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Firefox and xulrunner vulnerabilities
vendor_ubuntu·2008-11-17·CVSS 4.3
CVE-2008-4582 [MEDIUM] Firefox and xulrunner vulnerabilities
Title: Firefox and xulrunner vulnerabilities
Summary: Firefox and xulrunner vulnerabilities
Liu Die Yu discovered an information disclosure vulnerability in Firefox
when using saved .url shortcut files. If a user were tricked into
downloading a crafted .url file and a crafted HTML file, an attacker
could steal information from the user's cache. (CVE-2008-4582)
Georgi Guninski, Michal Zalewsk and Chris Evans discovered that the
same-origin check in Firefox could be bypassed. If a user were tricked
into opening a malicious website, an attacker could obtain private
information from data stored in the images, or discover information
about software on the user's computer. This issue only affects Firefox 2.
(CVE-2008-5012)
It was discovered that Firefox did not properly check if the Flash
mo
Red Hat
Mozilla -moz-binding property bypasses security checks on codebase principals
vendor_redhat·2008-11-12·CVSS 7.5
CVE-2008-5023 [HIGH] Mozilla -moz-binding property bypasses security checks on codebase principals
Mozilla -moz-binding property bypasses security checks on codebase principals
Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to bypass the protection mechanism for codebase principals and execute arbitrary script via the -moz-binding CSS property in a signed JAR file.
GHSA
GHSA-w4jm-xq46-3m5g: Firefox 3
ghsa_unreviewed·2022-05-14
CVE-2008-5023 [HIGH] CWE-20 GHSA-w4jm-xq46-3m5g: Firefox 3
Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to bypass the protection mechanism for codebase principals and execute arbitrary script via the -moz-binding CSS property in a signed JAR file.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00004.htmlhttp://secunia.com/advisories/32684http://secunia.com/advisories/32693http://secunia.com/advisories/32694http://secunia.com/advisories/32695http://secunia.com/advisories/32713http://secunia.com/advisories/32714http://secunia.com/advisories/32721http://secunia.com/advisories/32778http://secunia.com/advisories/32845http://secunia.com/advisories/32853http://secunia.com/advisories/34501http://sunsolve.sun.com/search/document.do?assetkey=1-26-256408-1http://ubuntu.com/usn/usn-667-1http://www.debian.org/security/2008/dsa-1669http://www.debian.org/security/2008/dsa-1671http://www.mandriva.com/security/advisories?name=MDVSA-2008:228http://www.mandriva.com/security/advisories?name=MDVSA-2008:230http://www.mozilla.org/security/announce/2008/mfsa2008-57.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0977.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0978.htmlhttp://www.securityfocus.com/bid/32281http://www.securitytracker.com/id?1021189http://www.us-cert.gov/cas/techalerts/TA08-319A.htmlhttp://www.vupen.com/english/advisories/2008/3146http://www.vupen.com/english/advisories/2009/0977https://bugzilla.mozilla.org/show_bug.cgi?id=424733https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9908https://www.redhat.com/archives/fedora-package-announce/2008-November/msg00366.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-November/msg00385.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-11/msg00004.htmlhttp://secunia.com/advisories/32684http://secunia.com/advisories/32693http://secunia.com/advisories/32694http://secunia.com/advisories/32695http://secunia.com/advisories/32713http://secunia.com/advisories/32714http://secunia.com/advisories/32721http://secunia.com/advisories/32778http://secunia.com/advisories/32845http://secunia.com/advisories/32853http://secunia.com/advisories/34501http://sunsolve.sun.com/search/document.do?assetkey=1-26-256408-1http://ubuntu.com/usn/usn-667-1http://www.debian.org/security/2008/dsa-1669http://www.debian.org/security/2008/dsa-1671http://www.mandriva.com/security/advisories?name=MDVSA-2008:228http://www.mandriva.com/security/advisories?name=MDVSA-2008:230http://www.mozilla.org/security/announce/2008/mfsa2008-57.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0977.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0978.htmlhttp://www.securityfocus.com/bid/32281http://www.securitytracker.com/id?1021189http://www.us-cert.gov/cas/techalerts/TA08-319A.htmlhttp://www.vupen.com/english/advisories/2008/3146http://www.vupen.com/english/advisories/2009/0977https://bugzilla.mozilla.org/show_bug.cgi?id=424733https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9908https://www.redhat.com/archives/fedora-package-announce/2008-November/msg00366.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-November/msg00385.html
2008-11-13
Published