7.5
CVSSv2

CVE-2008-2806

Published: 07/07/2008 Updated: 11/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Mozilla Firefox prior to 2.0.0.15 and SeaMonkey prior to 1.1.10 on Mac OS X allow remote malicious users to bypass the Same Origin Policy and create arbitrary socket connections via a crafted Java applet, related to the Java Embedding Plugin (JEP) and Java LiveConnect.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox 2.0.0.14

mozilla firefox 2.0.0.2

mozilla firefox 2.0.0.12

mozilla firefox 2.0.0.13

mozilla firefox 2.0_.1

mozilla firefox 2.0_.10

mozilla seamonkey 1.1.1

mozilla seamonkey 1.1.2

mozilla seamonkey 1.1

mozilla thunderbird 2.0_.12

mozilla thunderbird 2.0_8

mozilla firefox 2.0.0.3

mozilla firefox 2.0

mozilla firefox 2.0_.6

mozilla firefox 2.0.0.11

mozilla firefox 2.0_.9

mozilla firefox 2.0_8

mozilla seamonkey 1.1.8

mozilla seamonkey 1.1.9

mozilla thunderbird 2.0_.6

mozilla thunderbird 2.0_.9

mozilla firefox 2.0_.7

mozilla seamonkey 1.1.6

mozilla seamonkey 1.1.7

mozilla thunderbird 2.0_.4

mozilla thunderbird 2.0_.5

mozilla firefox 2.0_.4

mozilla firefox 2.0_.5

mozilla seamonkey 1.1.3

mozilla seamonkey 1.1.4

mozilla seamonkey 1.1.5

mozilla thunderbird 2.0_.13

mozilla thunderbird 2.0_.14

Vendor Advisories

Various flaws were discovered in the browser engine By tricking a user into opening a malicious web page, an attacker could cause a denial of service via application crash, or possibly execute arbitrary code with the privileges of the user invoking the program (CVE-2008-2798, CVE-2008-2799) ...
Mozilla Foundation Security Advisory 2008-28 Arbitrary socket connections with Java LiveConnect on Mac OS X Announced July 1, 2008 Reporter Gregory Fleischer Impact High Products Firefox, SeaMonkey Fixed in ...