Description
Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 do not properly escape HTML in file:// URLs in directory listings, which allows remote attackers to conduct cross-site scripting (XSS) attacks or have unspecified other impact via a crafted filename.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-1607-1 | New iceweasel packages fix several vulnerabilities |
Debian DSA |
DSA-1615-1 | New xulrunner packages fix several vulnerabilities |
Debian DSA |
DSA-1697-1 | New iceape packages fix several vulnerabilities |
EUVD |
EUVD-2008-2801 | Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 do not properly escape HTML in file:// URLs in directory listings, which allows remote attackers to conduct cross-site scripting (XSS) attacks or have unspecified other impact via a crafted filename. |
Ubuntu USN |
USN-619-1 | Firefox vulnerabilities |
References
History
No history.
Subscriptions
Mozilla
Subscribe
Firefox
Subscribe
Seamonkey
Subscribe
Thunderbird
Subscribe
Redhat
Subscribe
Advanced Workstation For The Itanium Processor
Subscribe
Desktop
Subscribe
Enterprise Linux
Subscribe
Enterprise Linux Desktop
Subscribe
Enterprise Linux Desktop Workstation
Subscribe
Fedora
Subscribe
Ubuntu
Subscribe
Ubuntu Linux
Subscribe
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-07T09:14:14.873Z
Reserved: 2008-06-20T00:00:00.000Z
Link: CVE-2008-2808
No data.
Status : Deferred
Published: 2008-07-07T23:41:00.000
Modified: 2025-04-09T00:30:58.490
Link: CVE-2008-2808
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
EUVD
Ubuntu USN