Lucene search

K
cveRedhatCVE-2008-5510
HistoryDec 17, 2008 - 11:30 p.m.

CVE-2008-5510

2008-12-1723:30:00
redhat
web.nvd.nist.gov
52
cve-2008-5510
mozilla firefox
thunderbird
seamonkey
css parser
null character
remote attackers
bypass protection

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

AI Score

9.7

Confidence

High

EPSS

0.005

Percentile

76.8%

The CSS parser in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 ignores the ‘\0’ escaped null character, which might allow remote attackers to bypass protection mechanisms such as sanitization routines.

Affected configurations

Nvd
Node
mozillafirefoxRange2.02.0.0.19
OR
mozillafirefoxRange3.03.0.5
OR
mozillaseamonkeyRange1.01.1.14
OR
mozillathunderbirdRange2.02.0.0.19
Node
canonicalubuntu_linuxMatch7.10
OR
canonicalubuntu_linuxMatch8.04lts
OR
canonicalubuntu_linuxMatch8.10
Node
debiandebian_linuxMatch4.0
OR
debiandebian_linuxMatch5.0
VendorProductVersionCPE
mozillafirefox*cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
mozillaseamonkey*cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:*
mozillathunderbird*cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
canonicalubuntu_linux7.10cpe:2.3:o:canonical:ubuntu_linux:7.10:*:*:*:*:*:*:*
canonicalubuntu_linux8.04cpe:2.3:o:canonical:ubuntu_linux:8.04:*:*:*:lts:*:*:*
canonicalubuntu_linux8.10cpe:2.3:o:canonical:ubuntu_linux:8.10:*:*:*:*:*:*:*
debiandebian_linux4.0cpe:2.3:o:debian:debian_linux:4.0:*:*:*:*:*:*:*
debiandebian_linux5.0cpe:2.3:o:debian:debian_linux:5.0:*:*:*:*:*:*:*

References

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

AI Score

9.7

Confidence

High

EPSS

0.005

Percentile

76.8%