CVE-2008-5022

HIGH
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

The nsXMLHttpRequest::NotifyEventListeners method in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to bypass the same-origin policy and execute arbitrary script via multiple listeners, which bypass the inner window check.

References

http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00004.html

http://secunia.com/advisories/32684

http://secunia.com/advisories/32693

http://secunia.com/advisories/32694

http://secunia.com/advisories/32695

http://secunia.com/advisories/32713

http://secunia.com/advisories/32714

http://secunia.com/advisories/32715

http://secunia.com/advisories/32721

http://secunia.com/advisories/32778

http://secunia.com/advisories/32798

http://secunia.com/advisories/32845

http://secunia.com/advisories/32853

http://secunia.com/advisories/33433

http://secunia.com/advisories/33434

http://secunia.com/advisories/34501

http://sunsolve.sun.com/search/document.do?assetkey=1-26-256408-1

http://ubuntu.com/usn/usn-667-1

http://www.debian.org/security/2008/dsa-1669

http://www.debian.org/security/2008/dsa-1671

http://www.debian.org/security/2009/dsa-1696

http://www.debian.org/security/2009/dsa-1697

http://www.mandriva.com/security/advisories?name=MDVSA-2008:228

http://www.mandriva.com/security/advisories?name=MDVSA-2008:230

http://www.mandriva.com/security/advisories?name=MDVSA-2008:235

http://www.mozilla.org/security/announce/2008/mfsa2008-56.html

http://www.redhat.com/support/errata/RHSA-2008-0976.html

http://www.redhat.com/support/errata/RHSA-2008-0977.html

http://www.redhat.com/support/errata/RHSA-2008-0978.html

http://www.securityfocus.com/bid/32281

http://www.securitytracker.com/id?1021188

http://www.us-cert.gov/cas/techalerts/TA08-319A.html

http://www.vupen.com/english/advisories/2008/3146

http://www.vupen.com/english/advisories/2009/0977

https://bugzilla.mozilla.org/show_bug.cgi?id=460002

https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11186

https://www.redhat.com/archives/fedora-package-announce/2008-November/msg00366.html

https://www.redhat.com/archives/fedora-package-announce/2008-November/msg00385.html

Details

Source: MITRE

Published: 2008-11-13

Updated: 2018-11-02

Type: CWE-287

Risk Information

CVSS v2

Base Score: 7.5

Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Impact Score: 6.4

Exploitability Score: 10

Severity: HIGH

Tenable Plugins

View all (52 total)

IDNameProductFamilySeverity
67766Oracle Linux 5 : firefox (ELSA-2008-0978)NessusOracle Linux Local Security Checks
critical
67765Oracle Linux 3 / 4 : seamonkey (ELSA-2008-0977)NessusOracle Linux Local Security Checks
critical
67764Oracle Linux 4 : thunderbird (ELSA-2008-0976)NessusOracle Linux Local Security Checks
critical
63402GLSA-201301-01 : Mozilla Products: Multiple vulnerabilities (BEAST)NessusGentoo Local Security Checks
critical
60498Scientific Linux Security Update : thunderbird on SL4.x, SL5.x i386/x86_64NessusScientific Linux Local Security Checks
critical
60495Scientific Linux Security Update : seamonkey on SL3.x, SL4.x i386/x86_64NessusScientific Linux Local Security Checks
critical
60494Scientific Linux Security Update : firefox on SL4.x, SL5.x i386/x86_64NessusScientific Linux Local Security Checks
critical
43715CentOS 4 / 5 : firefox (CESA-2008:0978)NessusCentOS Local Security Checks
critical
43714CentOS 4 / 5 : thunderbird (CESA-2008:0976)NessusCentOS Local Security Checks
critical
41511SuSE 10 Security Update : gecko-sdk and mozilla-xulrunner (ZYPP Patch Number 5813)NessusSuSE Local Security Checks
critical
41465SuSE 10 Security Update : MozillaFirefox (ZYPP Patch Number 5826)NessusSuSE Local Security Checks
critical
40131openSUSE Security Update : seamonkey (seamonkey-326)NessusSuSE Local Security Checks
critical
40072openSUSE Security Update : mozilla-xulrunner181 (mozilla-xulrunner181-329)NessusSuSE Local Security Checks
critical
39894openSUSE Security Update : MozillaThunderbird (MozillaThunderbird-333)NessusSuSE Local Security Checks
critical
39884openSUSE Security Update : MozillaFirefox (MozillaFirefox-334)NessusSuSE Local Security Checks
critical
37735Fedora 10 : thunderbird-2.0.0.18-1.fc10 (2008-9901)NessusFedora Local Security Checks
critical
37649Ubuntu 6.06 LTS / 7.10 / 8.04 LTS / 8.10 : mozilla-thunderbird, thunderbird vulnerabilities (USN-668-1)NessusUbuntu Local Security Checks
critical
37572Mandriva Linux Security Advisory : firefox (MDVSA-2008:230)NessusMandriva Local Security Checks
critical
37285Mandriva Linux Security Advisory : mozilla-firefox (MDVSA-2008:228)NessusMandriva Local Security Checks
critical
37099Mandriva Linux Security Advisory : mozilla-thunderbird (MDVSA-2008:235)NessusMandriva Local Security Checks
critical
36711Ubuntu 6.06 LTS / 7.10 / 8.04 LTS / 8.10 : firefox, firefox-3.0, xulrunner-1.9 vulnerabilities (USN-667-1)NessusUbuntu Local Security Checks
critical
36485CentOS 3 / 4 : seamonkey (CESA-2008:0977)NessusCentOS Local Security Checks
critical
35314Debian DSA-1697-1 : iceape - several vulnerabilitiesNessusDebian Local Security Checks
critical
35313Debian DSA-1696-1 : icedove - several vulnerabilitiesNessusDebian Local Security Checks
critical
34967SuSE 10 Security Update : gecko-sdk and mozilla-xulrunner (ZYPP Patch Number 5811)NessusSuSE Local Security Checks
critical
34961openSUSE 10 Security Update : seamonkey (seamonkey-5815)NessusSuSE Local Security Checks
critical
34960openSUSE 10 Security Update : mozilla-xulrunner181 (mozilla-xulrunner181-5820)NessusSuSE Local Security Checks
critical
34958openSUSE 10 Security Update : MozillaThunderbird (MozillaThunderbird-5825)NessusSuSE Local Security Checks
critical
34957openSUSE 10 Security Update : MozillaFirefox (MozillaFirefox-5812)NessusSuSE Local Security Checks
critical
34950Debian DSA-1671-1 : iceweasel - several vulnerabilitiesNessusDebian Local Security Checks
critical
34941SuSE 10 Security Update : MozillaFirefox (ZYPP Patch Number 5786)NessusSuSE Local Security Checks
critical
34938Debian DSA-1669-1 : xulrunner - several vulnerabilitiesNessusDebian Local Security Checks
critical
34842RHEL 4 / 5 : thunderbird (RHSA-2008:0976)NessusRed Hat Local Security Checks
critical
34837Fedora 9 : thunderbird-2.0.0.18-1.fc9 (2008-9859)NessusFedora Local Security Checks
critical
34836Fedora 8 : thunderbird-2.0.0.18-1.fc8 (2008-9807)NessusFedora Local Security Checks
critical
4762Mozilla Thunderbird < 2.0.0.18 Multiple VulnerabilitiesNessus Network MonitorSMTP Clients
medium
34819Mozilla Thunderbird < 2.0.0.18 Multiple VulnerabilitiesNessusWindows
high
34778Fedora 9 : Miro-1.2.7-2.fc9 / cairo-dock-1.6.3.1-1.fc9.1 / chmsee-1.0.1-6.fc9 / devhelp-0.19.1-6.fc9 / etc (2008-9669)NessusFedora Local Security Checks
critical
34777Fedora 8 : Miro-1.2.7-2.fc8 / blam-1.8.3-19.fc8 / cairo-dock-1.6.3.1-1.fc8.1 / chmsee-1.0.0-5.31.fc8 / etc (2008-9667)NessusFedora Local Security Checks
critical
34771FreeBSD : mozilla -- multiple vulnerabilities (f29fea8f-b19f-11dd-a55e-00163e000016)NessusFreeBSD Local Security Checks
critical
4753SeaMonkey < 1.1.13 Multiple VulnerabilitiesNessus Network MonitorWeb Clients
medium
4752Mozilla Firefox 3.x < 3.0.4 Multiple VulnerabilitiesNessus Network MonitorWeb Clients
medium
4751Mozilla Firefox < 2.0.0.18 Multiple VulnerabilitiesNessus Network MonitorWeb Clients
medium
34768SeaMonkey < 1.1.13 Multiple VulnerabilitiesNessusWindows
high
34767Firefox 3.0.x < 3.0.4 Multiple VulnerabilitiesNessusWindows
high
34766Firefox < 2.0.0.18 Multiple VulnerabilitiesNessusWindows
high
34764RHEL 4 / 5 : firefox (RHSA-2008:0978)NessusRed Hat Local Security Checks
critical
34763RHEL 2.1 / 3 / 4 : seamonkey (RHSA-2008:0977)NessusRed Hat Local Security Checks
critical
801316Mozilla Thunderbird < 2.0.0.18 Multiple VulnerabilitiesLog Correlation EngineSMTP Clients
high
800876SeaMonkey < 1.1.13 Multiple VulnerabilitiesLog Correlation EngineWeb Clients
high
800751Firefox 3.x < 3.0.4 Multiple VulnerabilitiesLog Correlation EngineWeb Clients
high
800741Firefox < 2.0.0.18 Multiple VulnerabilitiesLog Correlation EngineWeb Clients
high