CVE-2008-0417

CVSS v2.0 4.3 (Medium)
43% Progress
EPSS 1.40 % (87th)
1.40% Progress
Affected Products 1
Advisories 8

CRLF injection vulnerability in Mozilla Firefox before 2.0.0.12 allows remote user-assisted web sites to corrupt the user's password store via newlines that are not properly handled when the user saves a password.

Weaknesses
CWE-94
Improper Control of Generation of Code ('Code Injection')
CVE Status
PUBLISHED
CNA
Red Hat, Inc.
Published Date
2008-02-08 22:00:00
(16 years ago)
Updated Date
2018-10-15 22:00:05
(6 years ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Mozilla Firefox 2.0.0.11 and prior versions cpe:2.3:a:mozilla:firefox <= 2.0.0.11
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...