CVE-2008-0415

Mozilla Firefox < 2.0.0.11 - XSS

Title source: rule

Description

Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8 allows remote attackers to execute script outside of the sandbox and conduct cross-site scripting (XSS) attacks via multiple vectors including the XMLDocument.load function, aka "JavaScript privilege escalation bugs."

References (65)

... and 45 more

Scores

EPSS 0.0200
EPSS Percentile 83.5%

Classification

CWE
CWE-79
Status draft

Affected Products (3)

mozilla/firefox < 2.0.0.11
mozilla/seamonkey < 1.1.7
mozilla/thunderbird < 2.0.0.11

Timeline

Published Feb 08, 2008
Tracked Since Feb 18, 2026