CVE-2008-5019

Mozilla Firefox < 2.0.0.18 - XSS

Title source: rule

Description

The session restore feature in Mozilla Firefox 3.x before 3.0.4 and 2.x before 2.0.0.18 allows remote attackers to violate the same origin policy to conduct cross-site scripting (XSS) attacks and execute arbitrary JavaScript with chrome privileges via unknown vectors.

Scores

EPSS 0.1282
EPSS Percentile 93.9%

Classification

CWE
CWE-79
Status published

Affected Products (7)

mozilla/firefox < 2.0.0.18
debian/debian_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
n/a/n/a

Timeline

Published Nov 13, 2008
Tracked Since Feb 18, 2026