Lucene search

K
mozillaMozilla FoundationMFSA2008-58
HistoryNov 12, 2008 - 12:00 a.m.

Parsing error in E4X default namespace — Mozilla

2008-11-1200:00:00
Mozilla Foundation
www.mozilla.org
18

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.015

Percentile

86.9%

Security researcher Chris Evans reported an error in the method used to parse the default namespace in an E4X document. The error was caused by quote characters in the namespace not being properly escaped. The severity of this issue was determined to be low.

Affected configurations

Vulners
Node
mozillafirefoxRange<2.0.0.18
OR
mozillafirefoxRange<3.0.4
OR
mozillaseamonkeyRange<1.1.13
OR
mozillathunderbirdRange<2.0.0.18
VendorProductVersionCPE
mozillafirefox*cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
mozillaseamonkey*cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:*
mozillathunderbird*cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.015

Percentile

86.9%