CVE-2008-5510
MEDIUM severity · CVSS 5
5CVSS MEDIUM
Summary
The CSS parser in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 ignores the '\0' escaped null character, which might allow remote attackers to bypass protection mechanisms such as sanitization routines.
Impact & exploitability
Attack vectorNetwork
Attack complexityLow
Privileges required—
User interaction—
Confidentiality impactNone
Integrity impact—
Availability impactNone
Exploit probability (EPSS)2%
AV:N/AC:L/Au:N/C:N/I:P/A:N
Affected products we track (1)
Recommendation
Apply the vendor fix in your normal patch cycle. Open any affected product above for its exact safe version.
Additional information
- NVD record
- http://secunia.com/advisories/33184Advisory
- http://secunia.com/advisories/33188Advisory
- http://secunia.com/advisories/33203Advisory
- http://secunia.com/advisories/33204Advisory
- http://secunia.com/advisories/33205Advisory
- http://secunia.com/advisories/33216Advisory
- http://secunia.com/advisories/33231Advisory
- http://secunia.com/advisories/33408Advisory