The implementation of digital signatures for JAR files in Mozilla Firefox 4.x through 5, SeaMonkey 2.x before 2.3, and possibly other products does not prevent calls from unsigned JavaScript code to signed code, which allows remote attackers to bypass the Same Origin Policy and gain privileges via a crafted web site, a different vulnerability than CVE-2008-2801.
CVSS Details
- CVSS 3.1 Base Score: 8.1
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade seamonkeyUpgrade linux-firefoxUpgrade thunderbirdUpgrade linux-thunderbirdUpgrade firefox | Dec 10, 2025 | Aug 16, 2011 |
| Gentoo Linux | — | Upgrade www-client/mozilla-firefox.Upgrade mail-client/thunderbird.Upgrade net-libs/xulrunner.Upgrade mail-client/thunderbird-bin.Upgrade www-client/seamonkey.Upgrade dev-libs/nss.Upgrade mail-client/mozilla-thunderbird.Upgrade www-client/firefox.Upgrade net-libs/xulrunner-bin.Upgrade www-client/firefox-bin.Upgrade mail-client/mozilla-thunderbird-bin.Upgrade www-client/seamonkey-bin.Upgrade www-client/icecat.Upgrade www-client/mozilla-firefox-bin. | Oct 30, 2017 | Aug 18, 2011 |
| Mfsa2011 29 | — | Upgrade to Mozilla Firefox version 6.0 | Aug 19, 2011 | Aug 16, 2011 |
| Mozilla Seamonkey | — | Upgrade to Mozilla SeaMonkey version 2.3.0 | Feb 2, 2012 | Aug 18, 2011 |
| Suse | — | Upgrade MozillaFirefox-translations-otherUpgrade MozillaFirefox-translations-commonUpgrade MozillaFirefoxUpgrade MozillaFirefox-translationsUpgrade MozillaFirefox-devel | Feb 17, 2015 | Jul 9, 2013 |
| Ubuntu | — | Upgrade firefox | Nov 8, 2024 | Aug 18, 2011 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub