CVE-2008-1234
Mozilla Firefox <2.0.0.13 - XSS
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 2.0.0.13, Thunderbird before 2.0.0.13, and SeaMonkey before 1.1.9 allows remote attackers to inject arbitrary web script or HTML via event handlers, aka "Universal XSS using event handlers."
References (51)
... and 31 more
Scores
EPSS
0.0719
EPSS Percentile
91.5%
Classification
CWE
CWE-79
Status
draft
Affected Products (3)
mozilla/firefox
< 2.0.0.12
mozilla/seamonkey
< 1.1.8
mozilla/thunderbird
< 2.0.0.12
Timeline
Published
Mar 27, 2008
Tracked Since
Feb 18, 2026