[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249622

 
 

909

 
 

195549

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2008-5503Date: (C)2008-12-17   (M)2024-02-09


The loadBindingDocument function in Mozilla Firefox 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 does not perform any security checks related to the same-domain policy, which allows remote attackers to read or access data from other domains via crafted XBL bindings.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 2.6
Exploit Score: 4.9
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: HIGH
Authentication: NONE
Confidentiality: PARTIAL
Integrity: NONE
Availability: NONE
  
Reference:
SECTRACK-1021424
SUNALERT-256408
SUNALERT-258748
BID-32882
SECUNIA-33184
SECUNIA-33189
SECUNIA-33204
SECUNIA-33205
SECUNIA-33231
SECUNIA-33232
SECUNIA-33408
SECUNIA-33415
SECUNIA-33421
SECUNIA-33433
SECUNIA-33434
SECUNIA-33523
SECUNIA-33547
SECUNIA-34501
SECUNIA-35080
ADV-2009-0977
DSA-1696
DSA-1697
DSA-1704
DSA-1707
MDVSA-2008:244
MDVSA-2009:012
RHSA-2008:1037
RHSA-2009:0002
USN-690-2
USN-690-3
USN-701-1
USN-701-2
http://www.mozilla.org/security/announce/2008/mfsa2008-61.html
https://bugzilla.mozilla.org/show_bug.cgi?id=379959
mozilla-xbl-information-disclosure(47409)
oval:org.mitre.oval:def:11423

CPE    54
cpe:/a:mozilla:thunderbird:2.0.0.14
cpe:/a:mozilla:thunderbird:2.0.0.16
cpe:/a:mozilla:thunderbird:2.0.0.17
cpe:/a:mozilla:thunderbird:2.0.0.12
...
OVAL    20
oval:org.secpod.oval:def:200409
oval:org.secpod.oval:def:600436
oval:org.secpod.oval:def:400064
oval:org.secpod.oval:def:700482
...

© SecPod Technologies