Lucene search

K
ubuntucveUbuntu.comUB:CVE-2008-0418
HistoryFeb 08, 2008 - 12:00 a.m.

CVE-2008-0418

2008-02-0800:00:00
ubuntu.com
ubuntu.com
19

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

EPSS

0.013

Percentile

86.3%

Directory traversal vulnerability in Mozilla Firefox before 2.0.0.12,
Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8, when using “flat”
addons, allows remote attackers to read arbitrary Javascript, image, and
stylesheet files via the chrome: URI scheme, as demonstrated by stealing
session information from sessionstore.js.

OSVersionArchitecturePackageVersionFilename
ubuntu6.06noarchfirefox< 1.5.dfsg+1.5.0.15~prepatch080202a-0ubuntu1UNKNOWN
ubuntu6.10noarchfirefox< 2.0.0.12+0nobinonly+2-0ubuntu0.6.10UNKNOWN
ubuntu7.04noarchfirefox< 2.0.0.12+1nobinonly+2-0ubuntu0.7.4UNKNOWN
ubuntu7.10noarchfirefox< 2.0.0.12+2nobinonly+2-0ubuntu0.7.10UNKNOWN
ubuntu8.04noarchfirefox< 2.0.0.12+2nobinonly+2-0ubuntu3UNKNOWN
ubuntu6.06noarchmozilla-thunderbird< 1.5.0.13+1.5.0.15~prepatch080227-0ubuntu0.6.06.0UNKNOWN
ubuntu6.10noarchmozilla-thunderbird< 1.5.0.13+1.5.0.15~prepatch080227-0ubuntu0.6.10.0UNKNOWN
ubuntu7.04noarchmozilla-thunderbird< 1.5.0.13+1.5.0.15~prepatch080227-0ubuntu0.7.04.0UNKNOWN
ubuntu7.10noarchthunderbird< 2.0.0.12+nobinonly-0ubuntu0.7.10.0UNKNOWN
ubuntu8.04noarchthunderbird< 2.0.0.12+nobinonly-0ubuntu1UNKNOWN
Rows per page:
1-10 of 141

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

EPSS

0.013

Percentile

86.3%