4.3

CVE-2008-4582

Mozilla Firefox 3.0.1 through 3.0.3, Firefox 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13, when running on Windows, do not properly identify the context of Windows .url shortcut files, which allows user-assisted remote attackers to bypass the Same Origin Policy and obtain sensitive information via an HTML document that is directly accessible through a filesystem, as demonstrated by documents in (1) local folders, (2) Windows share folders, and (3) RAR archives, and as demonstrated by IFRAMEs referencing shortcuts that point to (a) about:cache?device=memory and (b) about:cache?device=disk, a variant of CVE-2008-2810.

Data is provided by the National Vulnerability Database (NVD)
DebianDebian Linux Version4.0
MozillaFirefox Version3.0.1
   MicrosoftWindows
MozillaFirefox Version3.0.2
   MicrosoftWindows
MozillaFirefox Version3.0.3
   MicrosoftWindows
MozillaFirefox Version2.0
   MicrosoftWindows
MozillaFirefox Version2.0.0.1
   MicrosoftWindows
MozillaFirefox Version2.0.0.10
   MicrosoftWindows
MozillaFirefox Version2.0.0.11
   MicrosoftWindows
MozillaFirefox Version2.0.0.12
   MicrosoftWindows
MozillaFirefox Version2.0.0.13
   MicrosoftWindows
MozillaFirefox Version2.0.0.14
   MicrosoftWindows
MozillaFirefox Version2.0.0.15
   MicrosoftWindows
MozillaFirefox Version2.0.0.16
   MicrosoftWindows
MozillaFirefox Version2.0.0.17
   MicrosoftWindows
CanonicalUbuntu Linux Version6.06 SwEditionlts
CanonicalUbuntu Linux Version7.10
CanonicalUbuntu Linux Version8.04 SwEditionlts
CanonicalUbuntu Linux Version8.10
MozillaSeamonkey Version1.0
   MicrosoftWindows
MozillaSeamonkey Version1.0 Updatealpha
   MicrosoftWindows
MozillaSeamonkey Version1.0 Updatebeta
   MicrosoftWindows
MozillaSeamonkey Version1.0.1
   MicrosoftWindows
MozillaSeamonkey Version1.0.2
   MicrosoftWindows
MozillaSeamonkey Version1.0.3
   MicrosoftWindows
MozillaSeamonkey Version1.0.4
   MicrosoftWindows
MozillaSeamonkey Version1.0.5
   MicrosoftWindows
MozillaSeamonkey Version1.0.6
   MicrosoftWindows
MozillaSeamonkey Version1.0.7
   MicrosoftWindows
MozillaSeamonkey Version1.0.8
   MicrosoftWindows
MozillaSeamonkey Version1.0.9
   MicrosoftWindows
MozillaSeamonkey Version1.1
   MicrosoftWindows
MozillaSeamonkey Version1.1 Updatealpha
   MicrosoftWindows
MozillaSeamonkey Version1.1 Updatebeta
   MicrosoftWindows
MozillaSeamonkey Version1.1.1
   MicrosoftWindows
MozillaSeamonkey Version1.1.2
   MicrosoftWindows
MozillaSeamonkey Version1.1.3
   MicrosoftWindows
MozillaSeamonkey Version1.1.4
   MicrosoftWindows
MozillaSeamonkey Version1.1.5
   MicrosoftWindows
MozillaSeamonkey Version1.1.6
   MicrosoftWindows
MozillaSeamonkey Version1.1.7
   MicrosoftWindows
MozillaSeamonkey Version1.1.8
   MicrosoftWindows
MozillaSeamonkey Version1.1.9
   MicrosoftWindows
MozillaSeamonkey Version1.1.10
   MicrosoftWindows
MozillaSeamonkey Version1.1.11
   MicrosoftWindows
MozillaSeamonkey Version1.1.12
   MicrosoftWindows
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 35.58% 0.967
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:P/I:N/A:N
http://secunia.com/advisories/33433
Third Party Advisory
Permissions Required
http://secunia.com/advisories/33434
Third Party Advisory
Permissions Required
http://secunia.com/advisories/34501
Third Party Advisory
Permissions Required
http://secunia.com/advisories/32845
Third Party Advisory
Permissions Required
http://secunia.com/advisories/32192
Third Party Advisory
Permissions Required
http://secunia.com/advisories/32684
Third Party Advisory
Permissions Required
http://secunia.com/advisories/32693
Third Party Advisory
Permissions Required
http://secunia.com/advisories/32714
Third Party Advisory
Permissions Required
http://secunia.com/advisories/32721
Third Party Advisory
Permissions Required
http://secunia.com/advisories/32778
Third Party Advisory
Permissions Required
http://secunia.com/advisories/32853
Third Party Advisory
Permissions Required
http://ubuntu.com/usn/usn-667-1
Third Party Advisory
http://www.securityfocus.com/bid/31611
Third Party Advisory
VDB Entry
http://www.securityfocus.com/bid/31747
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id?1021190
Third Party Advisory
VDB Entry
http://www.us-cert.gov/cas/techalerts/TA08-319A.html
Third Party Advisory
US Government Resource