7.5

CVE-2008-2806

Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 on Mac OS X allow remote attackers to bypass the Same Origin Policy and create arbitrary socket connections via a crafted Java applet, related to the Java Embedding Plugin (JEP) and Java LiveConnect.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mozilla ≫ Firefox Version 2.0
Mozilla ≫ Firefox Version 2.0 Update beta_1
Mozilla ≫ Firefox Version 2.0 Update rc2
Mozilla ≫ Firefox Version 2.0 Update rc3
Mozilla ≫ Firefox Version 2.0.0.2
Mozilla ≫ Firefox Version 2.0.0.3
Mozilla ≫ Firefox Version 2.0.0.11
Mozilla ≫ Firefox Version 2.0.0.12
Mozilla ≫ Firefox Version 2.0.0.13
Mozilla ≫ Firefox Version 2.0.0.14
Mozilla ≫ Firefox Version 2.0_.1
Mozilla ≫ Firefox Version 2.0_.4
Mozilla ≫ Firefox Version 2.0_.5
Mozilla ≫ Firefox Version 2.0_.6
Mozilla ≫ Firefox Version 2.0_.7
Mozilla ≫ Firefox Version 2.0_.9
Mozilla ≫ Firefox Version 2.0_.10
Mozilla ≫ Firefox Version 2.0_8
Mozilla ≫ Seamonkey Version 1.1 Update beta
Mozilla ≫ Seamonkey Version 1.1.1
Mozilla ≫ Seamonkey Version 1.1.2
Mozilla ≫ Seamonkey Version 1.1.3
Mozilla ≫ Seamonkey Version 1.1.4
Mozilla ≫ Seamonkey Version 1.1.5
Mozilla ≫ Seamonkey Version 1.1.6
Mozilla ≫ Seamonkey Version 1.1.7
Mozilla ≫ Seamonkey Version 1.1.8
Mozilla ≫ Seamonkey Version 1.1.9
Mozilla ≫ Thunderbird Version 2.0_.4
Mozilla ≫ Thunderbird Version 2.0_.5
Mozilla ≫ Thunderbird Version 2.0_.6
Mozilla ≫ Thunderbird Version 2.0_.9
Mozilla ≫ Thunderbird Version 2.0_.12
Mozilla ≫ Thunderbird Version 2.0_.13
Mozilla ≫ Thunderbird Version 2.0_.14
Mozilla ≫ Thunderbird Version 2.0_8
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.55% 0.83
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://secunia.com/advisories/31023
http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.383152
http://lists.opensuse.org/opensuse-security-announce/2008-07/msg00004.html
http://secunia.com/advisories/30898
http://secunia.com/advisories/30911
Vendor Advisory
http://secunia.com/advisories/31005
http://secunia.com/advisories/31008
http://secunia.com/advisories/31021
http://secunia.com/advisories/31076
http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.384911
http://wiki.rpath.com/Advisories:rPSA-2008-0216
http://www.mozilla.org/projects/security/known-vulnerabilities.html#firefox2.0.0.15
http://www.securityfocus.com/archive/1/494080/100/0/threaded
http://www.securityfocus.com/bid/30038
http://www.securitytracker.com/id?1020419
http://www.ubuntu.com/usn/usn-619-1
http://www.vupen.com/english/advisories/2008/1993/references
https://issues.rpath.com/browse/RPL-2646
https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00288.html
https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00295.html
http://www.mozilla.org/security/announce/2008/mfsa2008-28.html
https://bugzilla.mozilla.org/show_bug.cgi?id=408329