V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2008-4582
DEB
MediumConfirmedExploit available

Mozilla Firefox 3.0.1 through 3.0.3, Firefox 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13, when running on Windows, do not properly…

CVSS
4.3
Medium
EPSS
0.36
p97
Published
2008-01-01
Updated
2008-01-01
Description

Mozilla Firefox 3.0.1 through 3.0.3, Firefox 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13, when running on Windows, do not properly identify the context of Windows .url shortcut files, which allows user-assisted remote attackers to bypass the Same Origin Policy and obtain sensitive information via an HTML document that is directly accessible through a filesystem, as demonstrated by documents in (1) local folders, (2) Windows share folders, and (3) RAR archives, and as demonstrated by IFRAMEs referencing shortcuts that point to (a) about:cache?device=memory and (b) about:cache?device=disk, a variant of CVE-2008-2810.

Tags · CWE
CWE-264
Affected products
Debian_linux
CVSS vector
AV:N/AC:M/Au:N/C:P/I:N/A:N
Timeline
2008-01-01
Published
2008-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: M
Medium
Authentication
Au: N
None (N)
Confidentiality Impact
C: P
Partial
Integrity Impact
I: N
None (N)
Availability Impact
A: N
None (N)
Exploit indicators
EPSS
0.356 · p97
Known exploited (KEV)
No
Known exploits — Сканер-ВС
32466
exploitdb · https://www.exploit-db.com/exploits/32466
Enterprise
9663
exploitdb · https://www.exploit-db.com/exploits/9663
Enterprise
Affected software
ProductVendorStatus
firefoxTracked
firefox-3.0Tracked
iceapeTracked
icedoveTracked
iceweaselTracked
seamonkeyTracked
xulrunnerTracked
xulrunnerTracked
xulrunner-1.9Tracked
debian_linux*Tracked
firefox*Tracked
firefox*Tracked
seamonkey*Tracked
ubuntu_linux*Tracked