Логотип exploitDog
bind:CVE-2008-1238
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2008-1238

Количество 6

Количество 6

ubuntu логотип

CVE-2008-1238

около 17 лет назад

Mozilla Firefox before 2.0.0.13 and SeaMonkey before 1.1.9, when generating the HTTP Referer header, does not list the entire URL when it contains Basic Authentication credentials without a username, which makes it easier for remote attackers to bypass application protection mechanisms that rely on Referer headers, such as with some Cross-Site Request Forgery (CSRF) mechanisms.

CVSS2: 5
EPSS: Низкий
redhat логотип

CVE-2008-1238

около 17 лет назад

Mozilla Firefox before 2.0.0.13 and SeaMonkey before 1.1.9, when generating the HTTP Referer header, does not list the entire URL when it contains Basic Authentication credentials without a username, which makes it easier for remote attackers to bypass application protection mechanisms that rely on Referer headers, such as with some Cross-Site Request Forgery (CSRF) mechanisms.

EPSS: Низкий
nvd логотип

CVE-2008-1238

около 17 лет назад

Mozilla Firefox before 2.0.0.13 and SeaMonkey before 1.1.9, when generating the HTTP Referer header, does not list the entire URL when it contains Basic Authentication credentials without a username, which makes it easier for remote attackers to bypass application protection mechanisms that rely on Referer headers, such as with some Cross-Site Request Forgery (CSRF) mechanisms.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2008-1238

около 17 лет назад

Mozilla Firefox before 2.0.0.13 and SeaMonkey before 1.1.9, when gener ...

CVSS2: 5
EPSS: Низкий
github логотип

GHSA-q345-fgmq-3pf3

около 3 лет назад

Mozilla Firefox before 2.0.0.13 and SeaMonkey before 1.1.9, when generating the HTTP Referer header, does not list the entire URL when it contains Basic Authentication credentials without a username, which makes it easier for remote attackers to bypass application protection mechanisms that rely on Referer headers, such as with some Cross-Site Request Forgery (CSRF) mechanisms.

EPSS: Низкий
oracle-oval логотип

ELSA-2008-0207

около 17 лет назад

ELSA-2008-0207: firefox security update (CRITICAL)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2008-1238

Mozilla Firefox before 2.0.0.13 and SeaMonkey before 1.1.9, when generating the HTTP Referer header, does not list the entire URL when it contains Basic Authentication credentials without a username, which makes it easier for remote attackers to bypass application protection mechanisms that rely on Referer headers, such as with some Cross-Site Request Forgery (CSRF) mechanisms.

CVSS2: 5
6%
Низкий
около 17 лет назад
redhat логотип
CVE-2008-1238

Mozilla Firefox before 2.0.0.13 and SeaMonkey before 1.1.9, when generating the HTTP Referer header, does not list the entire URL when it contains Basic Authentication credentials without a username, which makes it easier for remote attackers to bypass application protection mechanisms that rely on Referer headers, such as with some Cross-Site Request Forgery (CSRF) mechanisms.

6%
Низкий
около 17 лет назад
nvd логотип
CVE-2008-1238

Mozilla Firefox before 2.0.0.13 and SeaMonkey before 1.1.9, when generating the HTTP Referer header, does not list the entire URL when it contains Basic Authentication credentials without a username, which makes it easier for remote attackers to bypass application protection mechanisms that rely on Referer headers, such as with some Cross-Site Request Forgery (CSRF) mechanisms.

CVSS2: 5
6%
Низкий
около 17 лет назад
debian логотип
CVE-2008-1238

Mozilla Firefox before 2.0.0.13 and SeaMonkey before 1.1.9, when gener ...

CVSS2: 5
6%
Низкий
около 17 лет назад
github логотип
GHSA-q345-fgmq-3pf3

Mozilla Firefox before 2.0.0.13 and SeaMonkey before 1.1.9, when generating the HTTP Referer header, does not list the entire URL when it contains Basic Authentication credentials without a username, which makes it easier for remote attackers to bypass application protection mechanisms that rely on Referer headers, such as with some Cross-Site Request Forgery (CSRF) mechanisms.

6%
Низкий
около 3 лет назад
oracle-oval логотип
ELSA-2008-0207

ELSA-2008-0207: firefox security update (CRITICAL)

около 17 лет назад

Уязвимостей на страницу