Multiple cross-site scripting (XSS) vulnerabilities in Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8 allow remote attackers to inject arbitrary web script or HTML via certain character encodings, including (1) a backspace character that is treated as whitespace, (2) 0x80 with Shift_JIS encoding, and (3) "zero-length non-ASCII sequences" in certain Asian character sets.
CVSS Details
- CVSS 3.1 Base Score: 6.1
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade mail-client/mozilla-thunderbird-bin.Upgrade www-client/mozilla-firefox.Upgrade www-client/mozilla-firefox-bin.Upgrade www-client/seamonkey-bin.Upgrade mail-client/mozilla-thunderbird.Upgrade net-libs/xulrunner.Upgrade www-client/seamonkey. | Oct 30, 2017 | Feb 11, 2008 |
| Mfsa2008 13 | — | Upgrade to Mozilla Firefox version 2.0.0.12 | Jun 14, 2012 | Feb 11, 2008 |
| Mozilla Seamonkey | — | Upgrade to Mozilla SeaMonkey version 1.1.8 | Feb 3, 2012 | Feb 11, 2008 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 2.0.0.12 | Feb 22, 2012 | Feb 11, 2008 |
| Oracle_linux | — | Upgrade firefoxUpgrade firefox-devel | Oct 16, 2024 | Feb 12, 2008 |
| Ubuntu | — | Upgrade firefox | Nov 8, 2024 | Feb 12, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub