Lucene search

K
ubuntucveUbuntu.comUB:CVE-2008-5510
HistoryDec 17, 2008 - 12:00 a.m.

CVE-2008-5510

2008-12-1700:00:00
ubuntu.com
ubuntu.com
27

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

EPSS

0.005

Percentile

76.8%

The CSS parser in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19,
Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 ignores
the ‘\0’ escaped null character, which might allow remote attackers to
bypass protection mechanisms such as sanitization routines.

OSVersionArchitecturePackageVersionFilename
ubuntu6.06noarchfirefox< 1.5.dfsg+1.5.0.15~prepatch080614i-0ubuntu1UNKNOWN
ubuntu7.10noarchfirefox< 2.0.0.19+nobinonly1-0ubuntu0.7.10.1UNKNOWN
ubuntu8.04noarchfirefox< 2.0.0.19+nobinonly1-0ubuntu0.8.04.1UNKNOWN
ubuntu10.04noarchfirefox< 3.0.5+nobinonly-0ubuntu0.8.04.1UNKNOWN
ubuntu10.10noarchfirefox< 3.0.5+nobinonly-0ubuntu0.8.04.1UNKNOWN
ubuntu11.04noarchfirefox< 3.0.5+nobinonly-0ubuntu0.8.04.1UNKNOWN
ubuntu8.04noarchfirefox-3.0< 3.0.5+nobinonly-0ubuntu0.8.04.1UNKNOWN
ubuntu8.10noarchfirefox-3.0< 3.0.5+nobinonly-0ubuntu0.8.10.1UNKNOWN
ubuntu9.04noarchfirefox-3.0< 3.0.5+nobinonly-0ubuntu1UNKNOWN
ubuntu6.06noarchmozilla-thunderbird< 1.5.0.13+1.5.0.15~prepatch080614i-0ubuntu0.6.06.1UNKNOWN
Rows per page:
1-10 of 311

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

EPSS

0.005

Percentile

76.8%