CVE-2008-5510Mozilla Firefox vulnerability

9 documents6 sources
Severity
5.0MEDIUMNVD
EPSS
1.0%
top 22.77%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 17
Latest updateMay 14

Description

The CSS parser in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 ignores the '\0' escaped null character, which might allow remote attackers to bypass protection mechanisms such as sanitization routines.

CVSS vector

AV:N/AC:L/C:N/I:P/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages3 packages

NVDmozilla/firefox2.02.0.0.19+1
NVDmozilla/seamonkey1.01.1.14
NVDmozilla/thunderbird2.02.0.0.19

Also affects: Debian Linux 4.0, 5.0, Ubuntu Linux 7.10, 8.04, 8.10

🔴Vulnerability Details

2
GHSA
GHSA-h25j-67c9-vc8j: The CSS parser in Mozilla Firefox 32022-05-14
CVEList
CVE-2008-5510: The CSS parser in Mozilla Firefox 32008-12-17

📋Vendor Advisories

5
Ubuntu
Firefox vulnerabilities2009-02-11
Ubuntu
Thunderbird vulnerabilities2009-01-06
Ubuntu
Firefox vulnerabilities2008-12-18
Ubuntu
Firefox and xulrunner vulnerabilities2008-12-17
Red Hat
Firefox null characters ignored by CSS parser2008-12-16

💬Community

1
Bugzilla
CVE-2008-5510 Firefox null characters ignored by CSS parser2008-12-12
CVE-2008-5510 — Mozilla Firefox vulnerability | cvebase