2.6
CVSSv2

CVE-2008-2933

Published: 17/07/2008 Updated: 11/10/2018
CVSS v2 Base Score: 2.6 | Impact Score: 2.9 | Exploitability Score: 4.9
VMScore: 231
Vector: AV:N/AC:H/Au:N/C:P/I:N/A:N

Vulnerability Summary

Mozilla Firefox prior to 2.0.0.16, and 3.x prior to 3.0.1, interprets '|' (pipe) characters in a command-line URI as requests to open multiple tabs, which allows remote malicious users to access chrome:i URIs, or read arbitrary local files via manipulations involving a series of URIs that is not entirely handled by a vector application, as exploited in conjunction with CVE-2008-2540. NOTE: this issue exists because of an insufficient fix for CVE-2005-2267.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox 0.10.1

mozilla firefox 0.8

mozilla firefox 1.0.2

mozilla firefox 1.0.3

mozilla firefox 1.0.4

mozilla firefox 1.5.0.10

mozilla firefox 1.5.0.11

mozilla firefox 1.5.0.7

mozilla firefox 1.5.0.8

mozilla firefox 1.5.6

mozilla firefox 1.5.7

mozilla firefox 1.5.8

mozilla firefox 2.0.0.13

mozilla firefox 2.0.0.14

mozilla firefox 2.0.0.8

mozilla firefox 2.0.0.9

mozilla firefox 2.0_8

mozilla firefox 3.0

mozilla firefox 0.9.2

mozilla firefox 0.9.3

mozilla firefox 1.0.7

mozilla firefox 1.0.8

mozilla firefox 1.5.0.3

mozilla firefox 1.5.0.4

mozilla firefox 1.5.2

mozilla firefox 1.5.3

mozilla firefox 2.0.0.1

mozilla firefox 2.0.0.10

mozilla firefox 2.0.0.4

mozilla firefox 2.0.0.5

mozilla firefox 2.0_.4

mozilla firefox 2.0_.5

mozilla firefox 0.10

mozilla firefox 1.0

mozilla firefox 1.0.1

mozilla firefox 1.5

mozilla firefox 1.5.0.1

mozilla firefox 1.5.0.5

mozilla firefox 1.5.0.6

mozilla firefox 1.5.4

mozilla firefox 1.5.5

mozilla firefox 2.0.0.11

mozilla firefox 2.0.0.12

mozilla firefox 2.0.0.6

mozilla firefox 2.0.0.7

mozilla firefox 2.0_.6

mozilla firefox 2.0_.7

mozilla firefox 2.0_.9

mozilla firefox 0.9

mozilla firefox 0.9.1

mozilla firefox 1.0.5

mozilla firefox 1.0.6

mozilla firefox 1.5.0.12

mozilla firefox 1.5.0.2

mozilla firefox 1.5.0.9

mozilla firefox 1.5.1

mozilla firefox 1.8

mozilla firefox 2.0

mozilla firefox 2.0.0.2

mozilla firefox 2.0.0.3

mozilla firefox 2.0_.1

mozilla firefox 2.0_.10

mozilla firefox

Vendor Advisories

USN-626-1 fixed vulnerabilities in xulrunner-19 The changes required that Devhelp, Epiphany, Midbrowser and Yelp also be updated to use the new xulrunner-19 ...
A flaw was discovered in the browser engine A variable could be made to overflow causing the browser to crash If a user were tricked into opening a malicious web page, an attacker could cause a denial of service or possibly execute arbitrary code with the privileges of the user invoking the program (CVE-2008-2785) ...
A flaw was discovered in the browser engine A variable could be made to overflow causing the browser to crash If a user were tricked into opening a malicious web page, an attacker could cause a denial of service or possibly execute arbitrary code with the privileges of the user invoking the program (CVE-2008-2785) ...
Several remote vulnerabilities have been discovered in Xulrunner, a runtime environment for XUL applications The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2008-2785 It was discovered that missing boundary checks on a reference counter for CSS objects can lead to the execution of arbitrary code CV ...
Several remote vulnerabilities have been discovered in Iceape an unbranded version of the Seamonkey internet suite The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2008-0016 Justin Schuh, Tom Cross and Peter Williams discovered a buffer overflow in the parser for UTF-8 URLs, which may lead to the ex ...
Several remote vulnerabilities have been discovered in the Iceweasel web browser, an unbranded version of the Firefox browser The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2008-2785 It was discovered that missing boundary checks on a reference counter for CSS objects can lead to the execution of a ...
Mozilla Foundation Security Advisory 2008-35 Command-line URLs launch multiple tabs when Firefox not running Announced July 15, 2008 Reporter Billy Rios, Ben Turner, Dan Veditz Impact Critical Products Firefox Fixed in ...

References

CWE-20https://bugzilla.mozilla.org/show_bug.cgi?id=441120http://www.securityfocus.com/bid/30242http://www.ubuntu.com/usn/usn-626-2http://secunia.com/advisories/31145http://www.kb.cert.org/vuls/id/130923http://secunia.com/advisories/31261http://secunia.com/advisories/31120http://secunia.com/advisories/31270http://secunia.com/advisories/31176http://secunia.com/advisories/31106http://www.ubuntu.com/usn/usn-623-1http://www.slackware.org/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.380974http://www.debian.org/security/2008/dsa-1614http://www.securitytracker.com/id?1020500https://issues.rpath.com/browse/RPL-2683http://secunia.com/advisories/31183http://www.ubuntu.com/usn/usn-626-1http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0238http://security.gentoo.org/glsa/glsa-200808-03.xmlhttp://secunia.com/advisories/31306http://secunia.com/advisories/31157http://www.debian.org/security/2008/dsa-1615http://secunia.com/advisories/31377http://www.redhat.com/support/errata/RHSA-2008-0598.htmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2008:148http://www.redhat.com/support/errata/RHSA-2008-0597.htmlhttp://www.novell.com/support/search.do?cmd=displayKC&docType=kc&externalId=InfoDocument-patchbuilder-readme5031400http://secunia.com/advisories/31129http://secunia.com/advisories/31121http://www.debian.org/security/2009/dsa-1697http://secunia.com/advisories/33433http://secunia.com/advisories/34501http://sunsolve.sun.com/search/document.do?assetkey=1-26-256408-1http://www.vupen.com/english/advisories/2009/0977http://www.mozilla.org/security/announce/2008/mfsa2008-35.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/43832https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11618http://www.securityfocus.com/archive/1/494860/100/0/threadedhttps://nvd.nist.govhttps://usn.ubuntu.com/626-2/https://www.kb.cert.org/vuls/id/130923