CVE-2008-5024
published 2008-11-13CVE-2008-5024: Mozilla Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 do not properly escape quote…
PriorityP336high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
3.64%
88.3th percentile
Mozilla Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 do not properly escape quote characters used for XML processing, which allows remote attackers to conduct XML injection attacks via the default namespace in an E4X document.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| mozilla | firefox | >= 2.0 < 2.0.0.18 | 2.0.0.18 |
| mozilla | firefox | >= 3.0 < 3.0.4 | 3.0.4 |
| mozilla | seamonkey | >= 1.0 < 1.1.13 | 1.1.13 |
| mozilla | thunderbird | >= 2.0 < 2.0.0.18 | 2.0.0.18 |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat7.5HIGH
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2008-11-26·CVSS 5.0
CVE-2008-5012 [MEDIUM] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Thunderbird vulnerabilities
Georgi Guninski, Michal Zalewsk and Chris Evans discovered that the same-origin
check in Thunderbird could be bypassed. If a user were tricked into opening a
malicious website, an attacker could obtain private information from data
stored in the images, or discover information about software on the user's
computer. (CVE-2008-5012)
Jesse Ruderman discovered that Thunderbird did not properly guard locks on
non-native objects. If a user had JavaScript enabled and were tricked into
opening malicious web content, an attacker could cause a browser crash and
possibly execute arbitrary code with user privileges. (CVE-2008-5014)
Several problems were discovered in the browser, layout and JavaScript engines.
If a user had Ja
Ubuntu
Firefox and xulrunner vulnerabilities
vendor_ubuntu·2008-11-17·CVSS 4.3
CVE-2008-4582 [MEDIUM] Firefox and xulrunner vulnerabilities
Title: Firefox and xulrunner vulnerabilities
Summary: Firefox and xulrunner vulnerabilities
Liu Die Yu discovered an information disclosure vulnerability in Firefox
when using saved .url shortcut files. If a user were tricked into
downloading a crafted .url file and a crafted HTML file, an attacker
could steal information from the user's cache. (CVE-2008-4582)
Georgi Guninski, Michal Zalewsk and Chris Evans discovered that the
same-origin check in Firefox could be bypassed. If a user were tricked
into opening a malicious website, an attacker could obtain private
information from data stored in the images, or discover information
about software on the user's computer. This issue only affects Firefox 2.
(CVE-2008-5012)
It was discovered that Firefox did not properly check if the Flash
mo
Red Hat
Mozilla parsing error in E4X default namespace
vendor_redhat·2008-11-12·CVSS 7.5
CVE-2008-5024 [HIGH] Mozilla parsing error in E4X default namespace
Mozilla parsing error in E4X default namespace
Mozilla Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 do not properly escape quote characters used for XML processing, which allows remote attackers to conduct XML injection attacks via the default namespace in an E4X document.
GHSA
GHSA-r9x5-wf23-5hh7: Mozilla Firefox 3
ghsa_unreviewed·2022-05-14
CVE-2008-5024 [HIGH] CWE-91 GHSA-r9x5-wf23-5hh7: Mozilla Firefox 3
Mozilla Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 do not properly escape quote characters used for XML processing, which allows remote attackers to conduct XML injection attacks via the default namespace in an E4X document.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00004.htmlhttp://secunia.com/advisories/32684http://secunia.com/advisories/32693http://secunia.com/advisories/32694http://secunia.com/advisories/32695http://secunia.com/advisories/32713http://secunia.com/advisories/32714http://secunia.com/advisories/32715http://secunia.com/advisories/32721http://secunia.com/advisories/32778http://secunia.com/advisories/32798http://secunia.com/advisories/32845http://secunia.com/advisories/32853http://secunia.com/advisories/33433http://secunia.com/advisories/33434http://secunia.com/advisories/34501http://sunsolve.sun.com/search/document.do?assetkey=1-26-256408-1http://ubuntu.com/usn/usn-667-1http://www.debian.org/security/2008/dsa-1669http://www.debian.org/security/2008/dsa-1671http://www.debian.org/security/2009/dsa-1696http://www.debian.org/security/2009/dsa-1697http://www.mandriva.com/security/advisories?name=MDVSA-2008:228http://www.mandriva.com/security/advisories?name=MDVSA-2008:230http://www.mandriva.com/security/advisories?name=MDVSA-2008:235http://www.mozilla.org/security/announce/2008/mfsa2008-58.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0976.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0977.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0978.htmlhttp://www.securityfocus.com/bid/32281http://www.securitytracker.com/id?1021192http://www.us-cert.gov/cas/techalerts/TA08-319A.htmlhttp://www.vupen.com/english/advisories/2008/3146http://www.vupen.com/english/advisories/2009/0977https://bugzilla.mozilla.org/show_bug.cgi?id=453915https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9063https://www.redhat.com/archives/fedora-package-announce/2008-November/msg00366.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-November/msg00385.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-11/msg00004.htmlhttp://secunia.com/advisories/32684http://secunia.com/advisories/32693http://secunia.com/advisories/32694http://secunia.com/advisories/32695http://secunia.com/advisories/32713http://secunia.com/advisories/32714http://secunia.com/advisories/32715http://secunia.com/advisories/32721http://secunia.com/advisories/32778http://secunia.com/advisories/32798http://secunia.com/advisories/32845http://secunia.com/advisories/32853http://secunia.com/advisories/33433http://secunia.com/advisories/33434http://secunia.com/advisories/34501http://sunsolve.sun.com/search/document.do?assetkey=1-26-256408-1http://ubuntu.com/usn/usn-667-1http://www.debian.org/security/2008/dsa-1669http://www.debian.org/security/2008/dsa-1671http://www.debian.org/security/2009/dsa-1696http://www.debian.org/security/2009/dsa-1697http://www.mandriva.com/security/advisories?name=MDVSA-2008:228http://www.mandriva.com/security/advisories?name=MDVSA-2008:230http://www.mandriva.com/security/advisories?name=MDVSA-2008:235http://www.mozilla.org/security/announce/2008/mfsa2008-58.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0976.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0977.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0978.htmlhttp://www.securityfocus.com/bid/32281http://www.securitytracker.com/id?1021192http://www.us-cert.gov/cas/techalerts/TA08-319A.htmlhttp://www.vupen.com/english/advisories/2008/3146http://www.vupen.com/english/advisories/2009/0977https://bugzilla.mozilla.org/show_bug.cgi?id=453915https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9063https://www.redhat.com/archives/fedora-package-announce/2008-November/msg00366.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-November/msg00385.html
2008-11-13
Published