CVE-2008-5503Mozilla Firefox vulnerability

9 documents6 sources
Severity
2.6LOWNVD
EPSS
1.2%
top 20.79%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 17
Latest updateMay 14

Description

The loadBindingDocument function in Mozilla Firefox 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 does not perform any security checks related to the same-domain policy, which allows remote attackers to read or access data from other domains via crafted XBL bindings.

CVSS vector

AV:N/AC:H/C:P/I:N/A:NExploitability: 4.9 | Impact: 2.9

Affected Packages3 packages

NVDmozilla/firefox2.0.0.18+18
NVDmozilla/seamonkey1.1.13+22
NVDmozilla/thunderbird2.0.0.18+9

🔴Vulnerability Details

2
GHSA
GHSA-xmfc-3wmp-72qq: The loadBindingDocument function in Mozilla Firefox 22022-05-14
CVEList
CVE-2008-5503: The loadBindingDocument function in Mozilla Firefox 22008-12-17

📋Vendor Advisories

5
Ubuntu
Thunderbird vulnerabilities2009-01-06
Ubuntu
Thunderbird vulnerabilities2009-01-06
Ubuntu
Firefox vulnerabilities2008-12-18
Ubuntu
Firefox vulnerabilities2008-12-18
Red Hat
Firefox 2 Information stealing via loadBindingDocument2008-12-16

💬Community

1
Bugzilla
CVE-2008-5503 Firefox 2 Information stealing via loadBindingDocument2008-12-12
CVE-2008-5503 — Mozilla Firefox vulnerability | cvebase