CVE-2008-4066
Mozilla Firefox - XSS
Title source: ruleDescription
Mozilla Firefox 2.0.0.14, and other versions before 2.0.0.17, allows remote attackers to bypass cross-site scripting (XSS) protection mechanisms and conduct XSS attacks via HTML-escaped low surrogate characters that are ignored by the HTML parser, as demonstrated by a "jav�ascript" sequence, aka "HTML escaped low surrogates bug."
References (44)
... and 24 more
Scores
EPSS
0.0120
EPSS Percentile
78.7%
Classification
CWE
CWE-79
Status
published
Affected Products (4)
mozilla/firefox
mozilla/firefox
mozilla/firefox
n/a/n/a
Timeline
Published
Sep 24, 2008
Tracked Since
Feb 18, 2026