CVE-2008-5513
published 2008-12-17CVE-2008-5513: Unspecified vulnerability in the session-restore feature in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19 allows remote attackers to bypass the same…
PriorityP415medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.78%
75.8th percentile
Unspecified vulnerability in the session-restore feature in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19 allows remote attackers to bypass the same origin policy, inject content into documents associated with other domains, and conduct cross-site scripting (XSS) attacks via unknown vectors related to restoration of SessionStore data.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| mozilla | firefox | >= 2.0 < 2.0.0.19 | 2.0.0.19 |
| mozilla | firefox | >= 3.0 < 3.0.5 | 3.0.5 |
| mozilla | seamonkey | >= 1.0 < 1.1.14 | 1.1.14 |
| mozilla | thunderbird | >= 2.0 < 2.0.0.19 | 2.0.0.19 |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_ubuntu10.0CRITICAL
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wpm2-x35v-w8w6: Unspecified vulnerability in the session-restore feature in Mozilla Firefox 3
ghsa_unreviewed·2022-05-14
CVE-2008-5513 [MEDIUM] CWE-79 GHSA-wpm2-x35v-w8w6: Unspecified vulnerability in the session-restore feature in Mozilla Firefox 3
Unspecified vulnerability in the session-restore feature in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19 allows remote attackers to bypass the same origin policy, inject content into documents associated with other domains, and conduct cross-site scripting (XSS) attacks via unknown vectors related to restoration of SessionStore data.
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2008-12-18·CVSS 10.0
CVE-2008-5510 [CRITICAL] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox vulnerabilities
Several flaws were discovered in the browser engine. These problems could allow
an attacker to crash the browser and possibly execute arbitrary code with user
privileges. (CVE-2008-5500)
Boris Zbarsky discovered that the same-origin check in Firefox could be
bypassed by utilizing XBL-bindings. An attacker could exploit this to read data
from other domains. (CVE-2008-5503)
Several problems were discovered in the JavaScript engine. An attacker could
exploit feed preview vulnerabilities to execute scripts from page content with
chrome privileges. (CVE-2008-5504)
Marius Schilder discovered that Firefox did not properly handle redirects to
an outside domain when an XMLHttpRequest was made to a same-origin resource.
It's possib
Ubuntu
Firefox and xulrunner vulnerabilities
vendor_ubuntu·2008-12-17·CVSS 10.0
CVE-2008-5502 [CRITICAL] Firefox and xulrunner vulnerabilities
Title: Firefox and xulrunner vulnerabilities
Summary: Firefox and xulrunner vulnerabilities
Several flaws were discovered in the browser engine. These problems could allow
an attacker to crash the browser and possibly execute arbitrary code with user
privileges. (CVE-2008-5500, CVE-2008-5501, CVE-2008-5502)
It was discovered that Firefox did not properly handle persistent cookie data.
If a user were tricked into opening a malicious website, an attacker could
write persistent data in the user's browser and track the user across browsing
sessions. (CVE-2008-5505)
Marius Schilder discovered that Firefox did not properly handle redirects to
an outside domain when an XMLHttpRequest was made to a same-origin resource.
It's possible that sensitive information could be revealed in the
XMLHttpR
Red Hat
Firefox XSS vulnerabilities in SessionStore
vendor_redhat·2008-12-16·CVSS 4.3
CVE-2008-5513 [MEDIUM] CWE-79 Firefox XSS vulnerabilities in SessionStore
Firefox XSS vulnerabilities in SessionStore
Unspecified vulnerability in the session-restore feature in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19 allows remote attackers to bypass the same origin policy, inject content into documents associated with other domains, and conduct cross-site scripting (XSS) attacks via unknown vectors related to restoration of SessionStore data.
No detection rules found.
No public exploits indexed.
http://secunia.com/advisories/33184http://secunia.com/advisories/33188http://secunia.com/advisories/33189http://secunia.com/advisories/33203http://secunia.com/advisories/33216http://secunia.com/advisories/33231http://secunia.com/advisories/33421http://secunia.com/advisories/33523http://secunia.com/advisories/34501http://sunsolve.sun.com/search/document.do?assetkey=1-26-256408-1http://www.debian.org/security/2009/dsa-1707http://www.mandriva.com/security/advisories?name=MDVSA-2008:244http://www.mandriva.com/security/advisories?name=MDVSA-2008:245http://www.mozilla.org/security/announce/2008/mfsa2008-69.htmlhttp://www.redhat.com/support/errata/RHSA-2008-1036.htmlhttp://www.redhat.com/support/errata/RHSA-2008-1037.htmlhttp://www.redhat.com/support/errata/RHSA-2009-0002.htmlhttp://www.securityfocus.com/bid/32882http://www.securitytracker.com/id?1021421http://www.ubuntu.com/usn/usn-690-2http://www.vupen.com/english/advisories/2009/0977https://exchange.xforce.ibmcloud.com/vulnerabilities/47418https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10389https://usn.ubuntu.com/690-1/http://secunia.com/advisories/33184http://secunia.com/advisories/33188http://secunia.com/advisories/33189http://secunia.com/advisories/33203http://secunia.com/advisories/33216http://secunia.com/advisories/33231http://secunia.com/advisories/33421http://secunia.com/advisories/33523http://secunia.com/advisories/34501http://sunsolve.sun.com/search/document.do?assetkey=1-26-256408-1http://www.debian.org/security/2009/dsa-1707http://www.mandriva.com/security/advisories?name=MDVSA-2008:244http://www.mandriva.com/security/advisories?name=MDVSA-2008:245http://www.mozilla.org/security/announce/2008/mfsa2008-69.htmlhttp://www.redhat.com/support/errata/RHSA-2008-1036.htmlhttp://www.redhat.com/support/errata/RHSA-2008-1037.htmlhttp://www.redhat.com/support/errata/RHSA-2009-0002.htmlhttp://www.securityfocus.com/bid/32882http://www.securitytracker.com/id?1021421http://www.ubuntu.com/usn/usn-690-2http://www.vupen.com/english/advisories/2009/0977https://exchange.xforce.ibmcloud.com/vulnerabilities/47418https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10389https://usn.ubuntu.com/690-1/
2008-12-17
Published