4.3
CVSSv2

CVE-2008-5019

Published: 13/11/2008 Updated: 13/02/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

The session restore feature in Mozilla Firefox 3.x prior to 3.0.4 and 2.x prior to 2.0.0.18 allows remote malicious users to violate the same origin policy to conduct cross-site scripting (XSS) attacks and execute arbitrary JavaScript with chrome privileges via unknown vectors.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox

debian debian linux 4.0

canonical ubuntu linux 6.06

canonical ubuntu linux 7.10

canonical ubuntu linux 8.04

canonical ubuntu linux 8.10

Vendor Advisories

Liu Die Yu discovered an information disclosure vulnerability in Firefox when using saved url shortcut files If a user were tricked into downloading a crafted url file and a crafted HTML file, an attacker could steal information from the user’s cache (CVE-2008-4582) ...
Synopsis Critical: firefox security update Type/Severity Security Advisory: Critical Topic An updated firefox package that fixes various security issues is nowavailable for Red Hat Enterprise Linux 4 and 5This update has been rated as having critical security impact by the RedHat Security Response Team ...
Synopsis Critical: seamonkey security update Type/Severity Security Advisory: Critical Topic Updated seamonkey packages that fix security issues are now available forRed Hat Enterprise Linux 21, Red Hat Enterprise Linux 3 and Red HatEnterprise Linux 4This update has been rated as having critical security ...
Mozilla Foundation Security Advisory 2008-53 XSS and JavaScript privilege escalation via session restore Announced November 12, 2008 Reporter David Bloom, moz_bug_r_a4 Impact Critical Products Firefox Fixed in ...