Описание
Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8 allows remote attackers to execute script outside of the sandbox and conduct cross-site scripting (XSS) attacks via multiple vectors including the XMLDocument.load function, aka "JavaScript privilege escalation bugs."
Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8 allows remote attackers to execute script outside of the sandbox and conduct cross-site scripting (XSS) attacks via multiple vectors including the XMLDocument.load function, aka "JavaScript privilege escalation bugs."
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2008-0415
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=386695%2C393761%2C393762%2C399298%2C407289%2C372075%2C363597
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=386695,393761,393762,399298,407289,372075,363597
- https://issues.rpath.com/browse/RPL-1995
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9897
- https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00274.html
- https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00309.html
- https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00381.html
- https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00905.html
- https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00946.html
- http://browser.netscape.com/releasenotes
- http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00006.html
- http://secunia.com/advisories/28754
- http://secunia.com/advisories/28758
- http://secunia.com/advisories/28766
- http://secunia.com/advisories/28808
- http://secunia.com/advisories/28815
- http://secunia.com/advisories/28818
- http://secunia.com/advisories/28839
- http://secunia.com/advisories/28864
- http://secunia.com/advisories/28865
- http://secunia.com/advisories/28877
- http://secunia.com/advisories/28879
- http://secunia.com/advisories/28924
- http://secunia.com/advisories/28939
- http://secunia.com/advisories/28958
- http://secunia.com/advisories/29049
- http://secunia.com/advisories/29086
- http://secunia.com/advisories/29098
- http://secunia.com/advisories/29164
- http://secunia.com/advisories/29167
- http://secunia.com/advisories/29211
- http://secunia.com/advisories/29567
- http://secunia.com/advisories/30327
- http://secunia.com/advisories/30620
- http://secunia.com/advisories/31043
- http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.445399
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-238492-1
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-239546-1
- http://support.novell.com/techcenter/psdb/6251b18e050302ebe7fe74294b55c818.html
- http://wiki.rpath.com/Advisories:rPSA-2008-0051
- http://wiki.rpath.com/Advisories:rPSA-2008-0093
- http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0093
- http://www.debian.org/security/2008/dsa-1484
- http://www.debian.org/security/2008/dsa-1485
- http://www.debian.org/security/2008/dsa-1489
- http://www.debian.org/security/2008/dsa-1506
- http://www.gentoo.org/security/en/glsa/glsa-200805-18.xml
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:048
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:062
- http://www.mozilla.org/security/announce/2008/mfsa2008-03.html
- http://www.redhat.com/support/errata/RHSA-2008-0103.html
- http://www.redhat.com/support/errata/RHSA-2008-0104.html
- http://www.redhat.com/support/errata/RHSA-2008-0105.html
- http://www.securityfocus.com/archive/1/487826/100/0/threaded
- http://www.securityfocus.com/archive/1/488002/100/0/threaded
- http://www.securityfocus.com/archive/1/488971/100/0/threaded
- http://www.securityfocus.com/bid/27683
- http://www.securitytracker.com/id?1019327
- http://www.ubuntu.com/usn/usn-576-1
- http://www.ubuntu.com/usn/usn-582-1
- http://www.ubuntu.com/usn/usn-582-2
- http://www.vupen.com/english/advisories/2008/0453/references
- http://www.vupen.com/english/advisories/2008/0454/references
- http://www.vupen.com/english/advisories/2008/0627/references
- http://www.vupen.com/english/advisories/2008/1793/references
- http://www.vupen.com/english/advisories/2008/2091/references
Связанные уязвимости
Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8 allows remote attackers to execute script outside of the sandbox and conduct cross-site scripting (XSS) attacks via multiple vectors including the XMLDocument.load function, aka "JavaScript privilege escalation bugs."
Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8 allows remote attackers to execute script outside of the sandbox and conduct cross-site scripting (XSS) attacks via multiple vectors including the XMLDocument.load function, aka "JavaScript privilege escalation bugs."
Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8 allows remote attackers to execute script outside of the sandbox and conduct cross-site scripting (XSS) attacks via multiple vectors including the XMLDocument.load function, aka "JavaScript privilege escalation bugs."
Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaM ...
ELSA-2008-0103: Critical: firefox security update (CRITICAL)