Описание
The session restore feature in Mozilla Firefox 3.x before 3.0.4 and 2.x before 2.0.0.18 allows remote attackers to violate the same origin policy to conduct cross-site scripting (XSS) attacks and execute arbitrary JavaScript with chrome privileges via unknown vectors.
The session restore feature in Mozilla Firefox 3.x before 3.0.4 and 2.x before 2.0.0.18 allows remote attackers to violate the same origin policy to conduct cross-site scripting (XSS) attacks and execute arbitrary JavaScript with chrome privileges via unknown vectors.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2008-5019
- https://access.redhat.com/errata/RHSA-2008:0977
- https://access.redhat.com/errata/RHSA-2008:0978
- https://access.redhat.com/security/cve/CVE-2008-5019
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=459906%2C460983
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=459906,460983
- https://bugzilla.redhat.com/show_bug.cgi?id=470889
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10943
- https://www.redhat.com/archives/fedora-package-announce/2008-November/msg00366.html
- https://www.redhat.com/archives/fedora-package-announce/2008-November/msg00385.html
- http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00004.html
- http://secunia.com/advisories/32684
- http://secunia.com/advisories/32693
- http://secunia.com/advisories/32694
- http://secunia.com/advisories/32695
- http://secunia.com/advisories/32713
- http://secunia.com/advisories/32721
- http://secunia.com/advisories/32778
- http://secunia.com/advisories/34501
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-256408-1
- http://ubuntu.com/usn/usn-667-1
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:228
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:230
- http://www.mozilla.org/security/announce/2008/mfsa2008-53.html
- http://www.redhat.com/support/errata/RHSA-2008-0977.html
- http://www.redhat.com/support/errata/RHSA-2008-0978.html
- http://www.securityfocus.com/bid/32281
- http://www.securitytracker.com/id?1021184
- http://www.us-cert.gov/cas/techalerts/TA08-319A.html
- http://www.vupen.com/english/advisories/2008/3146
- http://www.vupen.com/english/advisories/2009/0977
Связанные уязвимости
The session restore feature in Mozilla Firefox 3.x before 3.0.4 and 2.x before 2.0.0.18 allows remote attackers to violate the same origin policy to conduct cross-site scripting (XSS) attacks and execute arbitrary JavaScript with chrome privileges via unknown vectors.
The session restore feature in Mozilla Firefox 3.x before 3.0.4 and 2.x before 2.0.0.18 allows remote attackers to violate the same origin policy to conduct cross-site scripting (XSS) attacks and execute arbitrary JavaScript with chrome privileges via unknown vectors.
The session restore feature in Mozilla Firefox 3.x before 3.0.4 and 2.x before 2.0.0.18 allows remote attackers to violate the same origin policy to conduct cross-site scripting (XSS) attacks and execute arbitrary JavaScript with chrome privileges via unknown vectors.
The session restore feature in Mozilla Firefox 3.x before 3.0.4 and 2. ...