CVE-2008-5024

Mozilla Firefox <3.0.4-2.0.0.18 & Thunderbird <2.0.0.18 & SeaMonkey...

Title source: llm
STIX 2.1

Description

Mozilla Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 do not properly escape quote characters used for XML processing, which allows remote attackers to conduct XML injection attacks via the default namespace in an E4X document.

References (38)

Core 38
Core References
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/3146
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2009/dsa-1697
Exploit, Issue Tracking, Vendor Advisory x_refsource_misc
https://bugzilla.mozilla.org/show_bug.cgi?id=453915
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2008/dsa-1671
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/32281
Third Party Advisory vendor-advisory x_refsource_fedora
https://www.redhat.com/archives/fedora-package-announce/2008-November/msg00366.html
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/32713
Third Party Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2008-0977.html
Third Party Advisory vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2008:230
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2009/0977
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/32695
Third Party Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2008-0978.html
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2008/dsa-1669
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/32778
Third Party Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2008-0976.html
Third Party Advisory vendor-advisory x_refsource_fedora
https://www.redhat.com/archives/fedora-package-announce/2008-November/msg00385.html
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/33433
Broken Link vendor-advisory x_refsource_sunalert
http://sunsolve.sun.com/search/document.do?assetkey=1-26-256408-1
Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00004.html
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/32694
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/32721
Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA08-319A.html
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/32853
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2009/dsa-1696
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1021192
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/32715
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/32693
Third Party Advisory vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2008:228
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/32845
Third Party Advisory vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2008:235
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/33434
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/32798
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/32684
Third Party Advisory vendor-advisory x_refsource_ubuntu
http://ubuntu.com/usn/usn-667-1
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/32714
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/34501

Scores

EPSS 0.0364
EPSS Percentile 88.1%

Details

CWE
CWE-91
Status published
Products (8)
canonical/ubuntu_linux 6.06
canonical/ubuntu_linux 7.10
canonical/ubuntu_linux 8.04
canonical/ubuntu_linux 8.10
debian/debian_linux 4.0
mozilla/firefox 2.0 - 2.0.0.18
mozilla/seamonkey 1.0 - 1.1.13
mozilla/thunderbird 2.0 - 2.0.0.18
Published Nov 13, 2008
Tracked Since Feb 18, 2026