Mozilla Firefox 3.x before 3.0.5 allows remote attackers to bypass intended privacy restrictions by using the persist attribute in an XUL element to create and access data entities that are similar to cookies.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade nsprUpgrade nss-pkcs11-develUpgrade nss-toolsUpgrade nss-develUpgrade nssUpgrade xulrunner-devel-unstableUpgrade xulrunner-develUpgrade nspr-develUpgrade firefoxUpgrade xulrunner | Dec 1, 2016 | Dec 17, 2008 |
| Freebsd | — | Upgrade thunderbirdUpgrade linux-seamonkeyUpgrade seamonkeyUpgrade firefoxUpgrade linux-thunderbirdUpgrade linux-firefox | Dec 10, 2025 | Dec 19, 2008 |
| Gentoo Linux | — | Upgrade www-client/seamonkey.Upgrade dev-libs/nss.Upgrade www-client/firefox.Upgrade www-client/mozilla-firefox-bin.Upgrade www-client/firefox-bin.Upgrade www-client/icecat.Upgrade www-client/seamonkey-bin.Upgrade net-libs/xulrunner-bin.Upgrade www-client/mozilla-firefox.Upgrade mail-client/mozilla-thunderbird.Upgrade mail-client/thunderbird.Upgrade mail-client/mozilla-thunderbird-bin.Upgrade net-libs/xulrunner.Upgrade mail-client/thunderbird-bin. | Oct 30, 2017 | Dec 17, 2008 |
| Mfsa2008 63 | — | Upgrade to Mozilla Firefox version 3.0.5 | Jun 14, 2012 | Dec 17, 2008 |
| Oracle_linux | — | Upgrade xulrunner-devel-unstableUpgrade xulrunner-develUpgrade xulrunnerUpgrade nsprUpgrade nss-pkcs11-develUpgrade nss-toolsUpgrade nspr-develUpgrade nss-develUpgrade firefoxUpgrade nss | Oct 16, 2024 | Dec 17, 2008 |
| Suse | — | Upgrade MozillaFirefox-translationsUpgrade MozillaFirefox | Feb 17, 2015 | Dec 17, 2008 |
| Ubuntu | — | Upgrade abrowserUpgrade firefox-3.0Upgrade xulrunner-1.9 | Nov 8, 2024 | Dec 17, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub