CVE-2008-2802

CVSS v2.0 7.5 (High)
75% Progress
EPSS 58.46 % (98th)
58.46% Progress
Affected Products 3
Advisories 9

Mozilla Firefox before 2.0.0.15, Thunderbird 2.0.0.14 and earlier, and SeaMonkey before 1.1.10 allow remote attackers to execute arbitrary code via an XUL document that includes a script from a chrome: URI that points to a fastload file, related to this file's "privilege level."

Weaknesses
CWE-264
Permissions, Privileges, and Access Controls
CVE Status
PUBLISHED
CNA
Red Hat, Inc.
Published Date
2008-07-07 23:41:00
(16 years ago)
Updated Date
2018-10-11 20:43:38
(6 years ago)

Affected Products

Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Mozilla Firefox 2.0.0.14 and prior versions cpe:2.3:a:mozilla:firefox <= 2.0.0.14
  Mozilla Firefox 2.0 cpe:2.3:a:mozilla:firefox:2.0
  Mozilla Firefox 2.0.0.1 cpe:2.3:a:mozilla:firefox:2.0.0.1
  Mozilla Firefox 2.0.0.2 cpe:2.3:a:mozilla:firefox:2.0.0.2
  Mozilla Firefox 2.0.0.3 cpe:2.3:a:mozilla:firefox:2.0.0.3
  Mozilla Firefox 2.0.0.4 cpe:2.3:a:mozilla:firefox:2.0.0.4
  Mozilla Firefox 2.0.0.5 cpe:2.3:a:mozilla:firefox:2.0.0.5
  Mozilla Firefox 2.0.0.6 cpe:2.3:a:mozilla:firefox:2.0.0.6
  Mozilla Firefox 2.0.0.7 cpe:2.3:a:mozilla:firefox:2.0.0.7
  Mozilla Firefox 2.0.0.8 cpe:2.3:a:mozilla:firefox:2.0.0.8
  Mozilla Firefox 2.0.0.9 cpe:2.3:a:mozilla:firefox:2.0.0.9
  Mozilla Firefox 2.0.0.10 cpe:2.3:a:mozilla:firefox:2.0.0.10
  Mozilla Firefox 2.0.0.11 cpe:2.3:a:mozilla:firefox:2.0.0.11
  Mozilla Firefox 2.0.0.12 cpe:2.3:a:mozilla:firefox:2.0.0.12
  Mozilla Firefox 2.0.0.13 cpe:2.3:a:mozilla:firefox:2.0.0.13
  Mozilla Seamonkey 1.1.9 and prior versions cpe:2.3:a:mozilla:seamonkey <= 1.1.9
  Mozilla Seamonkey 1.1 cpe:2.3:a:mozilla:seamonkey:1.1
  Mozilla Seamonkey 1.1.2 cpe:2.3:a:mozilla:seamonkey:1.1.2
  Mozilla Seamonkey 1.1.3 cpe:2.3:a:mozilla:seamonkey:1.1.3
  Mozilla Seamonkey 1.1.4 cpe:2.3:a:mozilla:seamonkey:1.1.4
  Mozilla Seamonkey 1.1.5 cpe:2.3:a:mozilla:seamonkey:1.1.5
  Mozilla Seamonkey 1.1.6 cpe:2.3:a:mozilla:seamonkey:1.1.6
  Mozilla Seamonkey 1.1.7 cpe:2.3:a:mozilla:seamonkey:1.1.7
  Mozilla Seamonkey 1.1.8 cpe:2.3:a:mozilla:seamonkey:1.1.8
  Mozilla Thunderbird 2.0.0.14 and prior versions cpe:2.3:a:mozilla:thunderbird <= 2.0.0.14
  Mozilla Thunderbird 2.0.0.0 cpe:2.3:a:mozilla:thunderbird:2.0.0.0
  Mozilla Thunderbird 2.0.0.1 cpe:2.3:a:mozilla:thunderbird:2.0.0.1
  Mozilla Thunderbird 2.0.0.2 cpe:2.3:a:mozilla:thunderbird:2.0.0.2
  Mozilla Thunderbird 2.0.0.3 cpe:2.3:a:mozilla:thunderbird:2.0.0.3
  Mozilla Thunderbird 2.0.0.4 cpe:2.3:a:mozilla:thunderbird:2.0.0.4
  Mozilla Thunderbird 2.0.0.5 cpe:2.3:a:mozilla:thunderbird:2.0.0.5
  Mozilla Thunderbird 2.0.0.6 cpe:2.3:a:mozilla:thunderbird:2.0.0.6
  Mozilla Thunderbird 2.0.0.8 cpe:2.3:a:mozilla:thunderbird:2.0.0.8
  Mozilla Thunderbird 2.0.0.9 cpe:2.3:a:mozilla:thunderbird:2.0.0.9
  Mozilla Thunderbird 2.0.0.11 cpe:2.3:a:mozilla:thunderbird:2.0.0.11
  Mozilla Thunderbird 2.0.0.12 cpe:2.3:a:mozilla:thunderbird:2.0.0.12
  Mozilla Thunderbird 2.0.0.13 cpe:2.3:a:mozilla:thunderbird:2.0.0.13
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...