Lucene search

K
ubuntucveUbuntu.comUB:CVE-2008-5024
HistoryNov 13, 2008 - 12:00 a.m.

CVE-2008-5024

2008-11-1300:00:00
ubuntu.com
ubuntu.com
23

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.015

Percentile

86.9%

Mozilla Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird
2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 do not properly escape
quote characters used for XML processing, which allows remote attackers to
conduct XML injection attacks via the default namespace in an E4X document.

OSVersionArchitecturePackageVersionFilename
ubuntu6.06noarchfirefox< 1.5.dfsg+1.5.0.15~prepatch080614h-0ubuntu1UNKNOWN
ubuntu7.10noarchfirefox< 2.0.0.18+nobinonly-0ubuntu0.7.10UNKNOWN
ubuntu8.04noarchfirefox< 2.0.0.18+nobinonly-0ubuntu0.8.04.1UNKNOWN
ubuntu8.04noarchfirefox-3.0< 3.0.4+nobinonly-0ubuntu0.8.04.1UNKNOWN
ubuntu8.10noarchfirefox-3.0< 3.0.4+nobinonly-0ubuntu0.8.10.1UNKNOWN
ubuntu6.06noarchmozilla-thunderbird< 1.5.0.13+1.5.0.15~prepatch080614h-0ubuntu0.6.06.1UNKNOWN
ubuntu8.04noarchseamonkey< 1.1.15+nobinonly-0ubuntu0.8.04.2UNKNOWN
ubuntu8.10noarchseamonkey< 1.1.15+nobinonly-0ubuntu0.8.10.2UNKNOWN
ubuntu7.10noarchthunderbird< 2.0.0.18+nobinonly-0ubuntu0.7.10.1UNKNOWN
ubuntu8.04noarchthunderbird< 2.0.0.18+nobinonly-0ubuntu0.8.04.1UNKNOWN
Rows per page:
1-10 of 161

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.015

Percentile

86.9%