Vulnerability Description
Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allow remote attackers to bypass the same origin policy and access portions of data from another domain via a JavaScript URL that redirects to the target resource, which generates an error if the target data does not have JavaScript syntax, which can be accessed using the window.onerror DOM API.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox | >= 2.0, < 2.0.0.19 |
| Mozilla | Seamonkey | >= 1.0, < 1.1.14 |
| Mozilla | Thunderbird | >= 2.0, < 2.0.0.19 |
| Canonical | Ubuntu Linux | 6.06 |
| Debian | Debian Linux | 4.0 |
Related Weaknesses (CWE)
References
- http://scary.beasts.org/security/CESA-2008-011.htmlThird Party Advisory
- http://secunia.com/advisories/33184Third Party Advisory
- http://secunia.com/advisories/33188Third Party Advisory
- http://secunia.com/advisories/33189Third Party Advisory
- http://secunia.com/advisories/33203Third Party Advisory
- http://secunia.com/advisories/33204Third Party Advisory
- http://secunia.com/advisories/33205Third Party Advisory
- http://secunia.com/advisories/33216Third Party Advisory
- http://secunia.com/advisories/33231Third Party Advisory
- http://secunia.com/advisories/33232Third Party Advisory
- http://secunia.com/advisories/33408Third Party Advisory
- http://secunia.com/advisories/33415Third Party Advisory
- http://secunia.com/advisories/33421Third Party Advisory
- http://secunia.com/advisories/33433Third Party Advisory
- http://secunia.com/advisories/33434Third Party Advisory
FAQ
What is CVE-2008-5507?
CVE-2008-5507 is a vulnerability with a CVSS score of 6.0 (MEDIUM). Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allow remote attackers to bypass the same origin policy and access portions o...
How severe is CVE-2008-5507?
CVE-2008-5507 has been rated MEDIUM with a CVSS base score of 6.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2008-5507?
Check the references section above for vendor advisories and patch information. Affected products include: Mozilla Firefox, Mozilla Seamonkey, Mozilla Thunderbird, Canonical Ubuntu Linux, Debian Debian Linux.