V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2008-3835
DEB
HighConfirmedExploit available

The nsXMLDocument::OnChannelRedirect function in Mozilla Firefox before 2.0.0.17, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 …

CVSS
7.5
High
EPSS
0.00
p28
Published
2008-01-01
Updated
2008-01-01
Description

The nsXMLDocument::OnChannelRedirect function in Mozilla Firefox before 2.0.0.17, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows remote attackers to bypass the Same Origin Policy and execute arbitrary JavaScript code via unknown vectors.

Tags · CWE
CWE-264
Affected products
Firefox ≤ 2.0.0.16FirefoxSeamonkeySeamonkey ≤ 1.1.11ThunderbirdThunderbird ≤ 2.0.0.16
CVSS vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Timeline
2008-01-01
Published
2008-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Authentication
Au: N
None (N)
Confidentiality Impact
C: P
Partial
Integrity Impact
I: P
Partial
Availability Impact
A: P
Partial
Exploit indicators
EPSS
0.001 · p28
Known exploited (KEV)
No
Known exploits — Сканер-ВС
32466
exploitdb · https://www.exploit-db.com/exploits/32466
Enterprise
9663
exploitdb · https://www.exploit-db.com/exploits/9663
Enterprise
Affected software
ProductVendorStatus
devhelpTracked
firefoxTracked
firefox-3.0Tracked
iceapeTracked
icedoveTracked
iceweaselTracked
seamonkeyTracked
seamonkeyTracked
seamonkeyTracked
seamonkeyTracked
thunderbirdTracked
thunderbirdTracked
thunderbirdTracked
xulrunnerTracked
xulrunnerTracked
xulrunner-1.9Tracked
firefox*Tracked
seamonkey*Tracked
thunderbird*Tracked