CVE-2008-5507
published 2008-12-17CVE-2008-5507: Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allow remote attackers to bypass the…
PriorityP424medium6CVSS 2.0
AVNACMAuSCPIPAP
EPSS
1.66%
74.0th percentile
Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allow remote attackers to bypass the same origin policy and access portions of data from another domain via a JavaScript URL that redirects to the target resource, which generates an error if the target data does not have JavaScript syntax, which can be accessed using the window.onerror DOM API.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| mozilla | firefox | >= 2.0 < 2.0.0.19 | 2.0.0.19 |
| mozilla | firefox | >= 3.0 < 3.0.5 | 3.0.5 |
| mozilla | seamonkey | >= 1.0 < 1.1.14 | 1.1.14 |
| mozilla | thunderbird | >= 2.0 < 2.0.0.19 | 2.0.0.19 |
CVSS provenance
nvdv2.06.0MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:P
vendor_ubuntu10.0CRITICAL
vendor_redhat6.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-q2h5-97m4-jvvg: Mozilla Firefox 3
ghsa_unreviewed·2022-05-14
CVE-2008-5507 [MEDIUM] CWE-200 GHSA-q2h5-97m4-jvvg: Mozilla Firefox 3
Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allow remote attackers to bypass the same origin policy and access portions of data from another domain via a JavaScript URL that redirects to the target resource, which generates an error if the target data does not have JavaScript syntax, which can be accessed using the window.onerror DOM API.
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2009-01-06·CVSS 10.0
CVE-2008-5500 [CRITICAL] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Thunderbird vulnerabilities
Several flaws were discovered in the browser engine. If a user had Javascript
enabled, these problems could allow an attacker to crash Thunderbird and
possibly execute arbitrary code with user privileges. (CVE-2008-5500)
Boris Zbarsky discovered that the same-origin check in Thunderbird could be
bypassed by utilizing XBL-bindings. If a user had Javascript enabled, an
attacker could exploit this to read data from other domains. (CVE-2008-5503)
Marius Schilder discovered that Thunderbird did not properly handle redirects
to an outside domain when an XMLHttpRequest was made to a same-origin resource.
When Javascript is enabled, it's possible that sensitive information could be
revealed in the XMLHttpRequest response.
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2009-01-06·CVSS 10.0
CVE-2008-5500 [CRITICAL] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Thunderbird vulnerabilities
Several flaws were discovered in the browser engine. If a user had Javascript
enabled, these problems could allow an attacker to crash Thunderbird and
possibly execute arbitrary code with user privileges. (CVE-2008-5500)
Boris Zbarsky discovered that the same-origin check in Thunderbird could be
bypassed by utilizing XBL-bindings. If a user had Javascript enabled, an
attacker could exploit this to read data from other domains. (CVE-2008-5503)
Marius Schilder discovered that Thunderbird did not properly handle redirects
to an outside domain when an XMLHttpRequest was made to a same-origin resource.
When Javascript is enabled, it's possible that sensitive information could be
revealed in the XMLHttpRequest response.
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2008-12-18·CVSS 10.0
CVE-2008-5503 [CRITICAL] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox vulnerabilities
Several flaws were discovered in the browser engine. These problems could allow
an attacker to crash the browser and possibly execute arbitrary code with user
privileges. (CVE-2008-5500)
Boris Zbarsky discovered that the same-origin check in Firefox could be
bypassed by utilizing XBL-bindings. An attacker could exploit this to read data
from other domains. (CVE-2008-5503)
Marius Schilder discovered that Firefox did not properly handle redirects to
an outside domain when an XMLHttpRequest was made to a same-origin resource.
It's possible that sensitive information could be revealed in the
XMLHttpRequest response. (CVE-2008-5506)
Chris Evans discovered that Firefox did not properly protect a user's data when
accessing a sam
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2008-12-18·CVSS 10.0
CVE-2008-5510 [CRITICAL] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox vulnerabilities
Several flaws were discovered in the browser engine. These problems could allow
an attacker to crash the browser and possibly execute arbitrary code with user
privileges. (CVE-2008-5500)
Boris Zbarsky discovered that the same-origin check in Firefox could be
bypassed by utilizing XBL-bindings. An attacker could exploit this to read data
from other domains. (CVE-2008-5503)
Several problems were discovered in the JavaScript engine. An attacker could
exploit feed preview vulnerabilities to execute scripts from page content with
chrome privileges. (CVE-2008-5504)
Marius Schilder discovered that Firefox did not properly handle redirects to
an outside domain when an XMLHttpRequest was made to a same-origin resource.
It's possib
Ubuntu
Firefox and xulrunner vulnerabilities
vendor_ubuntu·2008-12-17·CVSS 10.0
CVE-2008-5502 [CRITICAL] Firefox and xulrunner vulnerabilities
Title: Firefox and xulrunner vulnerabilities
Summary: Firefox and xulrunner vulnerabilities
Several flaws were discovered in the browser engine. These problems could allow
an attacker to crash the browser and possibly execute arbitrary code with user
privileges. (CVE-2008-5500, CVE-2008-5501, CVE-2008-5502)
It was discovered that Firefox did not properly handle persistent cookie data.
If a user were tricked into opening a malicious website, an attacker could
write persistent data in the user's browser and track the user across browsing
sessions. (CVE-2008-5505)
Marius Schilder discovered that Firefox did not properly handle redirects to
an outside domain when an XMLHttpRequest was made to a same-origin resource.
It's possible that sensitive information could be revealed in the
XMLHttpR
Red Hat
Firefox Cross-domain data theft via script redirect error message
vendor_redhat·2008-12-16·CVSS 6.0
CVE-2008-5507 [MEDIUM] Firefox Cross-domain data theft via script redirect error message
Firefox Cross-domain data theft via script redirect error message
Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allow remote attackers to bypass the same origin policy and access portions of data from another domain via a JavaScript URL that redirects to the target resource, which generates an error if the target data does not have JavaScript syntax, which can be accessed using the window.onerror DOM API.
No detection rules found.
No public exploits indexed.
http://scary.beasts.org/security/CESA-2008-011.htmlhttp://secunia.com/advisories/33184http://secunia.com/advisories/33188http://secunia.com/advisories/33189http://secunia.com/advisories/33203http://secunia.com/advisories/33204http://secunia.com/advisories/33205http://secunia.com/advisories/33216http://secunia.com/advisories/33231http://secunia.com/advisories/33232http://secunia.com/advisories/33408http://secunia.com/advisories/33415http://secunia.com/advisories/33421http://secunia.com/advisories/33433http://secunia.com/advisories/33434http://secunia.com/advisories/33523http://secunia.com/advisories/33547http://secunia.com/advisories/34501http://secunia.com/advisories/35080http://sunsolve.sun.com/search/document.do?assetkey=1-26-256408-1http://sunsolve.sun.com/search/document.do?assetkey=1-26-258748-1http://www.debian.org/security/2009/dsa-1696http://www.debian.org/security/2009/dsa-1697http://www.debian.org/security/2009/dsa-1704http://www.debian.org/security/2009/dsa-1707http://www.mandriva.com/security/advisories?name=MDVSA-2008:244http://www.mandriva.com/security/advisories?name=MDVSA-2008:245http://www.mandriva.com/security/advisories?name=MDVSA-2009:012http://www.mozilla.org/security/announce/2008/mfsa2008-65.htmlhttp://www.redhat.com/support/errata/RHSA-2008-1036.htmlhttp://www.redhat.com/support/errata/RHSA-2008-1037.htmlhttp://www.redhat.com/support/errata/RHSA-2009-0002.htmlhttp://www.securityfocus.com/archive/1/499353/100/0/threadedhttp://www.securityfocus.com/bid/32882http://www.securitytracker.com/id?1021423http://www.ubuntu.com/usn/usn-690-2http://www.ubuntu.com/usn/usn-701-1http://www.ubuntu.com/usn/usn-701-2http://www.vupen.com/english/advisories/2009/0977https://bugzilla.mozilla.org/show_bug.cgi?id=461735https://exchange.xforce.ibmcloud.com/vulnerabilities/47413https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9376https://usn.ubuntu.com/690-1/https://usn.ubuntu.com/690-3/http://scary.beasts.org/security/CESA-2008-011.htmlhttp://secunia.com/advisories/33184http://secunia.com/advisories/33188http://secunia.com/advisories/33189http://secunia.com/advisories/33203http://secunia.com/advisories/33204http://secunia.com/advisories/33205http://secunia.com/advisories/33216http://secunia.com/advisories/33231http://secunia.com/advisories/33232http://secunia.com/advisories/33408http://secunia.com/advisories/33415http://secunia.com/advisories/33421http://secunia.com/advisories/33433http://secunia.com/advisories/33434http://secunia.com/advisories/33523http://secunia.com/advisories/33547http://secunia.com/advisories/34501http://secunia.com/advisories/35080http://sunsolve.sun.com/search/document.do?assetkey=1-26-256408-1http://sunsolve.sun.com/search/document.do?assetkey=1-26-258748-1http://www.debian.org/security/2009/dsa-1696http://www.debian.org/security/2009/dsa-1697http://www.debian.org/security/2009/dsa-1704http://www.debian.org/security/2009/dsa-1707http://www.mandriva.com/security/advisories?name=MDVSA-2008:244http://www.mandriva.com/security/advisories?name=MDVSA-2008:245http://www.mandriva.com/security/advisories?name=MDVSA-2009:012http://www.mozilla.org/security/announce/2008/mfsa2008-65.htmlhttp://www.redhat.com/support/errata/RHSA-2008-1036.htmlhttp://www.redhat.com/support/errata/RHSA-2008-1037.htmlhttp://www.redhat.com/support/errata/RHSA-2009-0002.htmlhttp://www.securityfocus.com/archive/1/499353/100/0/threadedhttp://www.securityfocus.com/bid/32882http://www.securitytracker.com/id?1021423http://www.ubuntu.com/usn/usn-690-2http://www.ubuntu.com/usn/usn-701-1http://www.ubuntu.com/usn/usn-701-2http://www.vupen.com/english/advisories/2009/0977https://bugzilla.mozilla.org/show_bug.cgi?id=461735https://exchange.xforce.ibmcloud.com/vulnerabilities/47413https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9376https://usn.ubuntu.com/690-1/https://usn.ubuntu.com/690-3/
2008-12-17
Published