Infesting you with Virus News
 

Vulnerabilities

Mozilla Firefox 2.x before 2.0.0.19 remote vulnerability (PC1-2008-1172)

Overview

Vulnerability chart

Risk level
  • Low
  • Medium
  • High
  • Extreme
  • Severe
Warning: security vulnerability level = severe
70 vulnerabilities(-y) found between 17 September, 2004 and 20 July, 2009.
Mozilla Firefox is identified as a web browser moved down from the Mozilla... more
See also: Firefox 2, mozilla-firefox, Mozilla JavaScript, The Mozilla JavaScript, Mozilla-based
30 files found: FirefoxSetu..., nsBookmarkT..., nsSessionStartup.js, nsSetDefaultBrowser.js, nsSessionStore.js, FeedProcessor.js, nsUrlClassi..., firefox.js, firefox-branding.js, reporter.js, nsSafebrows..., FeedWriter.js, nsUrlClassi..., nsURLFormatter.js, FeedConverter.js... more
A vulnerability in Mozilla Firefox 2.x before 2.0.0.19 was identified.
Remote Access
Unknown patch
availability
Patch implementation
unknown

References to Advisories, Solutions, and Tools

Description:

By running the vulnerability found in Mozilla Firefox 2.x before 2.0.0.19, remote attackers are able to run arbitrary JavaScript with chrome rights through vectors associated with the feed preview.

Impact:

By running the vulnerability identified in Mozilla Firefox 2.x before 2.0.0.19, remote attackers may gain administrator access. This vulnerability also offers partial confidentiality, integrity, and availability violation. Moreover, the information can be revealed and changes can be made without any authorization. With the help of this vulnerability, a service can be broken up.

References:https://bugzilla.mozilla.org/show_bug.cgi?id=453526
http://www.mozilla.org/security/announce/2008/mfsa2008-62.html

Impact

CVSS Severity

CVSS Version 2 Metrics:

CVSS v2 Base Score:7.5 (HIGH)Access Vector:N/A
Impact Subscore: 6.4Access Complexity: Low
Exploitability Subscore: 10.0Authentication: Not required to exploit
Impact Type:Provides unauthorized access, Allows partial confidentiality, integrity, and availability violation; Allows unauthorized disclosure of information; Allows disruption of service

Say something interesting!

Name:
Email:
Website:
Comment:
Please type 5-digit security code below:
Captcha image for spam protection

Latest Comments

July 31, 2010
http://temple-b .. 6/fha-203k.htmlfha 203k, :(, http://uksoccer .. sy-grammar.htmleasy grammar, hbt,... more..
July 31, 2010
http://thedukes .. ncy-meyers.htmlnancy meyers, 8332, http://maillots .. /***-girl.html*** girl,... more..
July 31, 2010
http://arthriti .. me-breasts.htmlprime breasts, jnin, http://rentacar .. ssing-tube.htmlpissing tube,... more..
more comments..
rss
Home > Vulnerabilities > PC1-2008-1172