CVE-2008-5510 — Mozilla Firefox vulnerability
9 documents6 sources
Severity
5.0MEDIUMNVD
EPSS
1.0%
top 22.77%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 17
Latest updateMay 14
Description
The CSS parser in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 ignores the '\0' escaped null character, which might allow remote attackers to bypass protection mechanisms such as sanitization routines.
CVSS vector
AV:N/AC:L/C:N/I:P/A:NExploitability: 10.0 | Impact: 2.9
Affected Packages3 packages
Also affects: Debian Linux 4.0, 5.0, Ubuntu Linux 7.10, 8.04, 8.10