Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 do not properly escape HTML in file:// URLs in directory listings, which allows remote attackers to conduct cross-site scripting (XSS) attacks or have unspecified other impact via a crafted filename.
CVSS Details
- CVSS 3.1 Base Score: 6.1
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade yelpUpgrade firefoxUpgrade xulrunner-develUpgrade devhelpUpgrade devhelp-develUpgrade xulrunner-devel-unstableUpgrade xulrunner | Dec 1, 2016 | Jul 7, 2008 |
| Gentoo Linux | — | Upgrade www-client/seamonkey-bin.Upgrade net-libs/xulrunner.Upgrade mail-client/mozilla-thunderbird-bin.Upgrade www-client/seamonkey.Upgrade net-libs/xulrunner-bin.Upgrade www-client/mozilla-firefox-bin.Upgrade www-client/mozilla-firefox.Upgrade mail-client/mozilla-thunderbird. | Oct 30, 2017 | Jul 7, 2008 |
| Mfsa2008 30 | — | Upgrade to Mozilla Firefox version 2.0.0.15 | Jun 14, 2012 | Jul 7, 2008 |
| Mozilla Seamonkey | — | Upgrade to Mozilla SeaMonkey version 1.1.10 | Feb 3, 2012 | Jul 7, 2008 |
| Oracle_linux | — | Upgrade xulrunner-devel-unstableUpgrade xulrunner-develUpgrade xulrunnerUpgrade firefoxUpgrade devhelp-develUpgrade devhelpUpgrade yelp | Oct 16, 2024 | Jul 7, 2008 |
| Suse | — | Upgrade suse-releaseUpgrade seamonkey-mailUpgrade seamonkey-venkmanUpgrade seamonkeyUpgrade seamonkey-dom-inspectorUpgrade MozillaFirefox-translationsUpgrade MozillaFirefoxUpgrade seamonkey-spellcheckerUpgrade seamonkey-irc | Feb 17, 2015 | Jul 7, 2008 |
| Ubuntu | — | Upgrade firefox | Nov 8, 2024 | Jul 7, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub