CVE-2008-4066

Mozilla Firefox - XSS

Title source: rule

Description

Mozilla Firefox 2.0.0.14, and other versions before 2.0.0.17, allows remote attackers to bypass cross-site scripting (XSS) protection mechanisms and conduct XSS attacks via HTML-escaped low surrogate characters that are ignored by the HTML parser, as demonstrated by a "jav&#56325ascript" sequence, aka "HTML escaped low surrogates bug."

Scores

EPSS 0.0120
EPSS Percentile 78.7%

Classification

CWE
CWE-79
Status published

Affected Products (4)

mozilla/firefox
mozilla/firefox
mozilla/firefox
n/a/n/a

Timeline

Published Sep 24, 2008
Tracked Since Feb 18, 2026