CVE-2008-3198

CVSS v2.0 7.5 (High)
75% Progress
EPSS 2.47 % (90th)
2.47% Progress
Affected Products 1
Advisories 1

Mozilla Firefox 3.x before 3.0.1 allows remote attackers to inject arbitrary web script into a chrome document via unspecified vectors, as demonstrated by injection into a XUL error page. NOTE: this can be leveraged to execute arbitrary code using CVE-2008-2933.

Weaknesses
CWE-94
Improper Control of Generation of Code ('Code Injection')
Related CVEs
CVE Status
PUBLISHED
CNA
MITRE
Published Date
2008-07-17 13:41:00
(16 years ago)
Updated Date
2017-08-08 01:31:39
(7 years ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Mozilla Firefox 3.0 cpe:2.3:a:mozilla:firefox:3.0
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...