Lucene search

K
cveMitreCVE-2008-3198
HistoryJul 17, 2008 - 1:41 p.m.

CVE-2008-3198

2008-07-1713:41:00
CWE-94
mitre
web.nvd.nist.gov
35
cve-2008-3198
mozilla firefox
remote attackers
web script injection
code execution
nvd

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.6

Confidence

Low

EPSS

0.025

Percentile

90.1%

Mozilla Firefox 3.x before 3.0.1 allows remote attackers to inject arbitrary web script into a chrome document via unspecified vectors, as demonstrated by injection into a XUL error page. NOTE: this can be leveraged to execute arbitrary code using CVE-2008-2933.

Affected configurations

Nvd
Node
mozillafirefoxMatch3.0
VendorProductVersionCPE
mozillafirefox3.0cpe:/a:mozilla:firefox:3.0:::

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.6

Confidence

Low

EPSS

0.025

Percentile

90.1%