Логотип exploitDog
bind:CVE-2008-1238
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2008-1238

Количество 6

Количество 6

ubuntu логотип

CVE-2008-1238

почти 18 лет назад

Mozilla Firefox before 2.0.0.13 and SeaMonkey before 1.1.9, when generating the HTTP Referer header, does not list the entire URL when it contains Basic Authentication credentials without a username, which makes it easier for remote attackers to bypass application protection mechanisms that rely on Referer headers, such as with some Cross-Site Request Forgery (CSRF) mechanisms.

CVSS2: 5
EPSS: Низкий
redhat логотип

CVE-2008-1238

почти 18 лет назад

Mozilla Firefox before 2.0.0.13 and SeaMonkey before 1.1.9, when generating the HTTP Referer header, does not list the entire URL when it contains Basic Authentication credentials without a username, which makes it easier for remote attackers to bypass application protection mechanisms that rely on Referer headers, such as with some Cross-Site Request Forgery (CSRF) mechanisms.

EPSS: Низкий
nvd логотип

CVE-2008-1238

почти 18 лет назад

Mozilla Firefox before 2.0.0.13 and SeaMonkey before 1.1.9, when generating the HTTP Referer header, does not list the entire URL when it contains Basic Authentication credentials without a username, which makes it easier for remote attackers to bypass application protection mechanisms that rely on Referer headers, such as with some Cross-Site Request Forgery (CSRF) mechanisms.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2008-1238

почти 18 лет назад

Mozilla Firefox before 2.0.0.13 and SeaMonkey before 1.1.9, when gener ...

CVSS2: 5
EPSS: Низкий
github логотип

GHSA-q345-fgmq-3pf3

почти 4 года назад

Mozilla Firefox before 2.0.0.13 and SeaMonkey before 1.1.9, when generating the HTTP Referer header, does not list the entire URL when it contains Basic Authentication credentials without a username, which makes it easier for remote attackers to bypass application protection mechanisms that rely on Referer headers, such as with some Cross-Site Request Forgery (CSRF) mechanisms.

EPSS: Низкий
oracle-oval логотип

ELSA-2008-0207

почти 18 лет назад

ELSA-2008-0207: firefox security update (CRITICAL)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2008-1238

Mozilla Firefox before 2.0.0.13 and SeaMonkey before 1.1.9, when generating the HTTP Referer header, does not list the entire URL when it contains Basic Authentication credentials without a username, which makes it easier for remote attackers to bypass application protection mechanisms that rely on Referer headers, such as with some Cross-Site Request Forgery (CSRF) mechanisms.

CVSS2: 5
5%
Низкий
почти 18 лет назад
redhat логотип
CVE-2008-1238

Mozilla Firefox before 2.0.0.13 and SeaMonkey before 1.1.9, when generating the HTTP Referer header, does not list the entire URL when it contains Basic Authentication credentials without a username, which makes it easier for remote attackers to bypass application protection mechanisms that rely on Referer headers, such as with some Cross-Site Request Forgery (CSRF) mechanisms.

5%
Низкий
почти 18 лет назад
nvd логотип
CVE-2008-1238

Mozilla Firefox before 2.0.0.13 and SeaMonkey before 1.1.9, when generating the HTTP Referer header, does not list the entire URL when it contains Basic Authentication credentials without a username, which makes it easier for remote attackers to bypass application protection mechanisms that rely on Referer headers, such as with some Cross-Site Request Forgery (CSRF) mechanisms.

CVSS2: 5
5%
Низкий
почти 18 лет назад
debian логотип
CVE-2008-1238

Mozilla Firefox before 2.0.0.13 and SeaMonkey before 1.1.9, when gener ...

CVSS2: 5
5%
Низкий
почти 18 лет назад
github логотип
GHSA-q345-fgmq-3pf3

Mozilla Firefox before 2.0.0.13 and SeaMonkey before 1.1.9, when generating the HTTP Referer header, does not list the entire URL when it contains Basic Authentication credentials without a username, which makes it easier for remote attackers to bypass application protection mechanisms that rely on Referer headers, such as with some Cross-Site Request Forgery (CSRF) mechanisms.

5%
Низкий
почти 4 года назад
oracle-oval логотип
ELSA-2008-0207

ELSA-2008-0207: firefox security update (CRITICAL)

почти 18 лет назад

Уязвимостей на страницу