CVE-2008-5504
published 2008-12-17CVE-2008-5504: Mozilla Firefox 2.x before 2.0.0.19 allows remote attackers to run arbitrary JavaScript with chrome privileges via vectors related to the feed preview, a…
PriorityP432high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
2.55%
83.5th percentile
Mozilla Firefox 2.x before 2.0.0.19 allows remote attackers to run arbitrary JavaScript with chrome privileges via vectors related to the feed preview, a different vulnerability than CVE-2008-3836.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 2.0.0.18 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_ubuntu10.0CRITICAL
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2008-12-18·CVSS 10.0
CVE-2008-5510 [CRITICAL] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox vulnerabilities
Several flaws were discovered in the browser engine. These problems could allow
an attacker to crash the browser and possibly execute arbitrary code with user
privileges. (CVE-2008-5500)
Boris Zbarsky discovered that the same-origin check in Firefox could be
bypassed by utilizing XBL-bindings. An attacker could exploit this to read data
from other domains. (CVE-2008-5503)
Several problems were discovered in the JavaScript engine. An attacker could
exploit feed preview vulnerabilities to execute scripts from page content with
chrome privileges. (CVE-2008-5504)
Marius Schilder discovered that Firefox did not properly handle redirects to
an outside domain when an XMLHttpRequest was made to a same-origin resource.
It's possib
Red Hat
Firefox 2 XSS attack vectors in feed preview
vendor_redhat·2008-12-16·CVSS 7.5
CVE-2008-5504 [HIGH] CWE-79 Firefox 2 XSS attack vectors in feed preview
Firefox 2 XSS attack vectors in feed preview
Mozilla Firefox 2.x before 2.0.0.19 allows remote attackers to run arbitrary JavaScript with chrome privileges via vectors related to the feed preview, a different vulnerability than CVE-2008-3836.
GHSA
GHSA-hph5-qh8m-x8v8: Mozilla Firefox 2
ghsa_unreviewed·2022-05-17·CVSS 7.5
CVE-2008-5504 [HIGH] GHSA-hph5-qh8m-x8v8: Mozilla Firefox 2
Mozilla Firefox 2.x before 2.0.0.19 allows remote attackers to run arbitrary JavaScript with chrome privileges via vectors related to the feed preview, a different vulnerability than CVE-2008-3836.
No detection rules found.
No public exploits indexed.
http://secunia.com/advisories/33184http://secunia.com/advisories/33189http://secunia.com/advisories/33231http://secunia.com/advisories/33523http://secunia.com/advisories/34501http://sunsolve.sun.com/search/document.do?assetkey=1-26-256408-1http://www.debian.org/security/2009/dsa-1707http://www.mandriva.com/security/advisories?name=MDVSA-2008:244http://www.mozilla.org/security/announce/2008/mfsa2008-62.htmlhttp://www.redhat.com/support/errata/RHSA-2008-1037.htmlhttp://www.securityfocus.com/bid/32882http://www.securitytracker.com/id?1021422http://www.ubuntu.com/usn/usn-690-2http://www.vupen.com/english/advisories/2009/0977https://bugzilla.mozilla.org/show_bug.cgi?id=453526https://exchange.xforce.ibmcloud.com/vulnerabilities/47410https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10781http://secunia.com/advisories/33184http://secunia.com/advisories/33189http://secunia.com/advisories/33231http://secunia.com/advisories/33523http://secunia.com/advisories/34501http://sunsolve.sun.com/search/document.do?assetkey=1-26-256408-1http://www.debian.org/security/2009/dsa-1707http://www.mandriva.com/security/advisories?name=MDVSA-2008:244http://www.mozilla.org/security/announce/2008/mfsa2008-62.htmlhttp://www.redhat.com/support/errata/RHSA-2008-1037.htmlhttp://www.securityfocus.com/bid/32882http://www.securitytracker.com/id?1021422http://www.ubuntu.com/usn/usn-690-2http://www.vupen.com/english/advisories/2009/0977https://bugzilla.mozilla.org/show_bug.cgi?id=453526https://exchange.xforce.ibmcloud.com/vulnerabilities/47410https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10781
2008-12-17
Published