CVE-2008-0415
CVE-2008-0415
Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8 allows remote attackers to execute script outside of the sandbox and conduct cross-site scripting (XSS) attacks via multiple vectors including the XMLDocument.load function, aka "JavaScript privilege escalation bugs."
Affected products
n/a · n/aWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
http://browser.netscape.com/releasenotes/http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00006.htmlhttps://bugzilla.mozilla.org/buglist.cgi?bug_id=386695%2C393761%2C393762%2C399298%2C407289%2C372075%2C363597http://secunia.com/advisories/28754http://secunia.com/advisories/28758http://secunia.com/advisories/28766http://secunia.com/advisories/28808http://secunia.com/advisories/28815http://secunia.com/advisories/28818http://secunia.com/advisories/28839http://secunia.com/advisories/28864http://secunia.com/advisories/28865