CVE-2008-5505Mozilla Firefox vulnerability

CWE-2645 documents5 sources
Severity
5.0MEDIUMNVD
EPSS
0.8%
top 25.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 17
Latest updateMay 14

Description

Mozilla Firefox 3.x before 3.0.5 allows remote attackers to bypass intended privacy restrictions by using the persist attribute in an XUL element to create and access data entities that are similar to cookies.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages1 packages

NVDmozilla/firefox3.0.4+4

🔴Vulnerability Details

1
GHSA
GHSA-7v9j-67p6-63jv: Mozilla Firefox 32022-05-14

📋Vendor Advisories

2
Ubuntu
Firefox and xulrunner vulnerabilities2008-12-17
Red Hat
Firefox 3 User tracking via XUL persist attribute2008-12-16

💬Community

1
Bugzilla
CVE-2008-5505 Firefox 3 User tracking via XUL persist attribute2008-12-12