CVE-2008-4060

CVSS v2.0 7.5 (High)
75% Progress
EPSS 48.90 % (98th)
48.90% Progress
Affected Products 3
Advisories 12

Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allow remote attackers to create documents that lack script-handling objects, and execute arbitrary code with chrome privileges, via vectors related to (1) the document.loadBindingDocument function and (2) XSLT.

Weaknesses
CWE-264
Permissions, Privileges, and Access Controls
CVE Status
PUBLISHED
CNA
Red Hat, Inc.
Published Date
2008-09-24 20:37:04
(16 years ago)
Updated Date
2017-09-29 01:31:57
(7 years ago)

Affected Products

Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Mozilla Firefox 2.0.0.16 and prior versions cpe:2.3:a:mozilla:firefox <= 2.0.0.16
  Mozilla Firefox 0.8 cpe:2.3:a:mozilla:firefox:0.8
  Mozilla Firefox 0.9 cpe:2.3:a:mozilla:firefox:0.9
  Mozilla Firefox 0.9 Rc cpe:2.3:a:mozilla:firefox:0.9:rc
  Mozilla Firefox 0.9.1 cpe:2.3:a:mozilla:firefox:0.9.1
  Mozilla Firefox 0.9.2 cpe:2.3:a:mozilla:firefox:0.9.2
  Mozilla Firefox 0.9.3 cpe:2.3:a:mozilla:firefox:0.9.3
  Mozilla Firefox 0.9 Rc cpe:2.3:a:mozilla:firefox:0.9_rc
  Mozilla Firefox 0.10 cpe:2.3:a:mozilla:firefox:0.10
  Mozilla Firefox 0.10.1 cpe:2.3:a:mozilla:firefox:0.10.1
  Mozilla Firefox 1.0 cpe:2.3:a:mozilla:firefox:1.0
  Mozilla Firefox 1.0.1 cpe:2.3:a:mozilla:firefox:1.0.1
  Mozilla Firefox 1.0.2 cpe:2.3:a:mozilla:firefox:1.0.2
  Mozilla Firefox 1.0.3 cpe:2.3:a:mozilla:firefox:1.0.3
  Mozilla Firefox 1.0.4 cpe:2.3:a:mozilla:firefox:1.0.4
  Mozilla Firefox 1.0.5 cpe:2.3:a:mozilla:firefox:1.0.5
  Mozilla Firefox 1.0.6 cpe:2.3:a:mozilla:firefox:1.0.6
  Mozilla Firefox 1.0.7 cpe:2.3:a:mozilla:firefox:1.0.7
  Mozilla Firefox 1.0.8 cpe:2.3:a:mozilla:firefox:1.0.8
  Mozilla Firefox 1.5 cpe:2.3:a:mozilla:firefox:1.5
  Mozilla Firefox 1.5 Beta1 cpe:2.3:a:mozilla:firefox:1.5:beta1
  Mozilla Firefox 1.5 Beta2 cpe:2.3:a:mozilla:firefox:1.5:beta2
  Mozilla Firefox 1.5.0.1 cpe:2.3:a:mozilla:firefox:1.5.0.1
  Mozilla Firefox 1.5.0.2 cpe:2.3:a:mozilla:firefox:1.5.0.2
  Mozilla Firefox 1.5.0.3 cpe:2.3:a:mozilla:firefox:1.5.0.3
  Mozilla Firefox 1.5.0.4 cpe:2.3:a:mozilla:firefox:1.5.0.4
  Mozilla Firefox 1.5.0.5 cpe:2.3:a:mozilla:firefox:1.5.0.5
  Mozilla Firefox 1.5.0.6 cpe:2.3:a:mozilla:firefox:1.5.0.6
  Mozilla Firefox 1.5.0.7 cpe:2.3:a:mozilla:firefox:1.5.0.7
  Mozilla Firefox 1.5.0.8 cpe:2.3:a:mozilla:firefox:1.5.0.8
  Mozilla Firefox 1.5.0.9 cpe:2.3:a:mozilla:firefox:1.5.0.9
  Mozilla Firefox 1.5.0.10 cpe:2.3:a:mozilla:firefox:1.5.0.10
  Mozilla Firefox 1.5.0.11 cpe:2.3:a:mozilla:firefox:1.5.0.11
  Mozilla Firefox 1.5.0.12 cpe:2.3:a:mozilla:firefox:1.5.0.12
  Mozilla Firefox 1.5.1 cpe:2.3:a:mozilla:firefox:1.5.1
  Mozilla Firefox 1.5.2 cpe:2.3:a:mozilla:firefox:1.5.2
  Mozilla Firefox 1.5.3 cpe:2.3:a:mozilla:firefox:1.5.3
  Mozilla Firefox 1.5.4 cpe:2.3:a:mozilla:firefox:1.5.4
  Mozilla Firefox 1.5.5 cpe:2.3:a:mozilla:firefox:1.5.5
  Mozilla Firefox 1.5.6 cpe:2.3:a:mozilla:firefox:1.5.6
  Mozilla Firefox 1.5.7 cpe:2.3:a:mozilla:firefox:1.5.7
  Mozilla Firefox 1.5.8 cpe:2.3:a:mozilla:firefox:1.5.8
  Mozilla Firefox 1.8 cpe:2.3:a:mozilla:firefox:1.8
  Mozilla Firefox 2.0 cpe:2.3:a:mozilla:firefox:2.0
  Mozilla Firefox 2.0.0.1 cpe:2.3:a:mozilla:firefox:2.0.0.1
  Mozilla Firefox 2.0.0.10 cpe:2.3:a:mozilla:firefox:2.0.0.10
  Mozilla Firefox 2.0.0.11 cpe:2.3:a:mozilla:firefox:2.0.0.11
  Mozilla Firefox 2.0.0.12 cpe:2.3:a:mozilla:firefox:2.0.0.12
  Mozilla Firefox 2.0.0.13 cpe:2.3:a:mozilla:firefox:2.0.0.13
  Mozilla Firefox 2.0.0.14 cpe:2.3:a:mozilla:firefox:2.0.0.14
  Mozilla Firefox 2.0.0.15 cpe:2.3:a:mozilla:firefox:2.0.0.15
  Mozilla Firefox 3.0 cpe:2.3:a:mozilla:firefox:3.0
  Mozilla Firefox 3.0.1 cpe:2.3:a:mozilla:firefox:3.0.1
  Mozilla Seamonkey cpe:2.3:a:mozilla:seamonkey
  Mozilla Seamonkey 1.1.11 and prior versions cpe:2.3:a:mozilla:seamonkey <= 1.1.11
  Mozilla Seamonkey 1.0 cpe:2.3:a:mozilla:seamonkey:1.0
  Mozilla Seamonkey 1.0 Alpha Edition cpe:2.3:a:mozilla:seamonkey:1.0:*:alpha
  Mozilla Seamonkey 1.0 Dev Edition cpe:2.3:a:mozilla:seamonkey:1.0:*:dev
  Mozilla Seamonkey 1.0 Beta cpe:2.3:a:mozilla:seamonkey:1.0:beta
  Mozilla Seamonkey 1.0.1 cpe:2.3:a:mozilla:seamonkey:1.0.1
  Mozilla Seamonkey 1.0.2 cpe:2.3:a:mozilla:seamonkey:1.0.2
  Mozilla Seamonkey 1.0.3 cpe:2.3:a:mozilla:seamonkey:1.0.3
  Mozilla Seamonkey 1.0.4 cpe:2.3:a:mozilla:seamonkey:1.0.4
  Mozilla Seamonkey 1.0.5 cpe:2.3:a:mozilla:seamonkey:1.0.5
  Mozilla Seamonkey 1.0.6 cpe:2.3:a:mozilla:seamonkey:1.0.6
  Mozilla Seamonkey 1.0.7 cpe:2.3:a:mozilla:seamonkey:1.0.7
  Mozilla Seamonkey 1.0.8 cpe:2.3:a:mozilla:seamonkey:1.0.8
  Mozilla Seamonkey 1.0.9 cpe:2.3:a:mozilla:seamonkey:1.0.9
  Mozilla Seamonkey 1.0.99 cpe:2.3:a:mozilla:seamonkey:1.0.99
  Mozilla Seamonkey 1.1 cpe:2.3:a:mozilla:seamonkey:1.1
  Mozilla Seamonkey 1.1.1 cpe:2.3:a:mozilla:seamonkey:1.1.1
  Mozilla Seamonkey 1.1.10 cpe:2.3:a:mozilla:seamonkey:1.1.10
  Mozilla Thunderbird cpe:2.3:a:mozilla:thunderbird
  Mozilla Thunderbird 2.0.0.16 and prior versions cpe:2.3:a:mozilla:thunderbird <= 2.0.0.16
  Mozilla Thunderbird 0.1 cpe:2.3:a:mozilla:thunderbird:0.1
  Mozilla Thunderbird 0.2 cpe:2.3:a:mozilla:thunderbird:0.2
  Mozilla Thunderbird 0.3 cpe:2.3:a:mozilla:thunderbird:0.3
  Mozilla Thunderbird 0.4 cpe:2.3:a:mozilla:thunderbird:0.4
  Mozilla Thunderbird 0.5 cpe:2.3:a:mozilla:thunderbird:0.5
  Mozilla Thunderbird 0.6 cpe:2.3:a:mozilla:thunderbird:0.6
  Mozilla Thunderbird 0.7 cpe:2.3:a:mozilla:thunderbird:0.7
  Mozilla Thunderbird 0.7.1 cpe:2.3:a:mozilla:thunderbird:0.7.1
  Mozilla Thunderbird 0.7.2 cpe:2.3:a:mozilla:thunderbird:0.7.2
  Mozilla Thunderbird 0.7.3 cpe:2.3:a:mozilla:thunderbird:0.7.3
  Mozilla Thunderbird 0.8 cpe:2.3:a:mozilla:thunderbird:0.8
  Mozilla Thunderbird 0.9 cpe:2.3:a:mozilla:thunderbird:0.9
  Mozilla Thunderbird 1.0 cpe:2.3:a:mozilla:thunderbird:1.0
  Mozilla Thunderbird 1.0.1 cpe:2.3:a:mozilla:thunderbird:1.0.1
  Mozilla Thunderbird 1.0.2 cpe:2.3:a:mozilla:thunderbird:1.0.2
  Mozilla Thunderbird 1.0.3 cpe:2.3:a:mozilla:thunderbird:1.0.3
  Mozilla Thunderbird 1.0.4 cpe:2.3:a:mozilla:thunderbird:1.0.4
  Mozilla Thunderbird 1.0.5 cpe:2.3:a:mozilla:thunderbird:1.0.5
  Mozilla Thunderbird 1.0.5 Beta cpe:2.3:a:mozilla:thunderbird:1.0.5:beta
  Mozilla Thunderbird 1.0.6 cpe:2.3:a:mozilla:thunderbird:1.0.6
  Mozilla Thunderbird 1.0.7 cpe:2.3:a:mozilla:thunderbird:1.0.7
  Mozilla Thunderbird 1.0.8 cpe:2.3:a:mozilla:thunderbird:1.0.8
  Mozilla Thunderbird 1.5 cpe:2.3:a:mozilla:thunderbird:1.5
  Mozilla Thunderbird 1.5 Beta2 cpe:2.3:a:mozilla:thunderbird:1.5:beta2
  Mozilla Thunderbird 1.5.0.1 cpe:2.3:a:mozilla:thunderbird:1.5.0.1
  Mozilla Thunderbird 1.5.0.2 cpe:2.3:a:mozilla:thunderbird:1.5.0.2
  Mozilla Thunderbird 1.5.0.3 cpe:2.3:a:mozilla:thunderbird:1.5.0.3
  Mozilla Thunderbird 1.5.0.4 cpe:2.3:a:mozilla:thunderbird:1.5.0.4
  Mozilla Thunderbird 1.5.0.6 cpe:2.3:a:mozilla:thunderbird:1.5.0.6
  Mozilla Thunderbird 1.5.0.7 cpe:2.3:a:mozilla:thunderbird:1.5.0.7
  Mozilla Thunderbird 1.5.0.8 cpe:2.3:a:mozilla:thunderbird:1.5.0.8
  Mozilla Thunderbird 1.5.0.9 cpe:2.3:a:mozilla:thunderbird:1.5.0.9
  Mozilla Thunderbird 1.5.0.10 cpe:2.3:a:mozilla:thunderbird:1.5.0.10
  Mozilla Thunderbird 1.5.0.11 cpe:2.3:a:mozilla:thunderbird:1.5.0.11
  Mozilla Thunderbird 1.5.1 cpe:2.3:a:mozilla:thunderbird:1.5.1
  Mozilla Thunderbird 1.5.2 cpe:2.3:a:mozilla:thunderbird:1.5.2
  Mozilla Thunderbird 1.7.1 cpe:2.3:a:mozilla:thunderbird:1.7.1
  Mozilla Thunderbird 1.7.3 cpe:2.3:a:mozilla:thunderbird:1.7.3
  Mozilla Thunderbird 2.0.0.0 cpe:2.3:a:mozilla:thunderbird:2.0.0.0
  Mozilla Thunderbird 2.0.0.1 cpe:2.3:a:mozilla:thunderbird:2.0.0.1
  Mozilla Thunderbird 2.0.0.2 cpe:2.3:a:mozilla:thunderbird:2.0.0.2
  Mozilla Thunderbird 2.0.0.3 cpe:2.3:a:mozilla:thunderbird:2.0.0.3
  Mozilla Thunderbird 2.0.0.4 cpe:2.3:a:mozilla:thunderbird:2.0.0.4
  Mozilla Thunderbird 2.0.0.5 cpe:2.3:a:mozilla:thunderbird:2.0.0.5
  Mozilla Thunderbird 2.0.0.6 cpe:2.3:a:mozilla:thunderbird:2.0.0.6
  Mozilla Thunderbird 2.0.0.8 cpe:2.3:a:mozilla:thunderbird:2.0.0.8
  Mozilla Thunderbird 2.0.0.9 cpe:2.3:a:mozilla:thunderbird:2.0.0.9
  Mozilla Thunderbird 2.0.0.11 cpe:2.3:a:mozilla:thunderbird:2.0.0.11
  Mozilla Thunderbird 2.0.0.12 cpe:2.3:a:mozilla:thunderbird:2.0.0.12
  Mozilla Thunderbird 2.0.0.13 cpe:2.3:a:mozilla:thunderbird:2.0.0.13
  Mozilla Thunderbird 2.0.0.14 cpe:2.3:a:mozilla:thunderbird:2.0.0.14
  Mozilla Thunderbird 2.0.0.15 cpe:2.3:a:mozilla:thunderbird:2.0.0.15
  Mozilla Thunderbird 2.0 .4 cpe:2.3:a:mozilla:thunderbird:2.0_.4
  Mozilla Thunderbird 2.0 .5 cpe:2.3:a:mozilla:thunderbird:2.0_.5
  Mozilla Thunderbird 2.0 .6 cpe:2.3:a:mozilla:thunderbird:2.0_.6
  Mozilla Thunderbird 2.0 .9 cpe:2.3:a:mozilla:thunderbird:2.0_.9
  Mozilla Thunderbird 2.0 .12 cpe:2.3:a:mozilla:thunderbird:2.0_.12
  Mozilla Thunderbird 2.0 .13 cpe:2.3:a:mozilla:thunderbird:2.0_.13
  Mozilla Thunderbird 2.0 .14 cpe:2.3:a:mozilla:thunderbird:2.0_.14
  Mozilla Thunderbird 2.0 8 cpe:2.3:a:mozilla:thunderbird:2.0_8
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...