[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248268

 
 

909

 
 

195051

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2008-5012Date: (C)2008-11-13   (M)2024-02-09


Mozilla Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 do not properly change the source URI when processing a canvas element and an HTTP redirect, which allows remote attackers to bypass the same origin policy and access arbitrary images that are not directly accessible to the attacker. NOTE: this issue can be leveraged to enumerate software on the client by performing redirections related to moz-icon.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 5.0
Exploit Score: 10.0
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: PARTIAL
Integrity: NONE
Availability: NONE
  
Reference:
SECTRACK-1021187
http://www.securityfocus.com/archive/1/498468
SUNALERT-256408
BID-32281
BID-32351
SECUNIA-32684
SECUNIA-32693
SECUNIA-32694
SECUNIA-32714
SECUNIA-32715
SECUNIA-32778
SECUNIA-32798
SECUNIA-32845
SECUNIA-32853
SECUNIA-33433
SECUNIA-33434
SECUNIA-34501
ADV-2008-3146
ADV-2009-0977
DSA-1669
DSA-1671
DSA-1696
DSA-1697
FEDORA-2008-9667
MDVSA-2008:228
MDVSA-2008:235
RHSA-2008:0976
RHSA-2008:0977
SUSE-SA:2008:055
TA08-319A
USN-667-1
http://scary.beasts.org/security/CESA-2008-009.html
http://scarybeastsecurity.blogspot.com/2008/11/firefox-cross-domain-image-theft-and.html
http://www.mozilla.org/security/announce/2008/mfsa2008-48.html
https://bugzilla.mozilla.org/show_bug.cgi?id=355126
https://bugzilla.mozilla.org/show_bug.cgi?id=451619
oval:org.mitre.oval:def:10750

CPE    134
cpe:/a:mozilla:thunderbird:2.0.0.14
cpe:/a:mozilla:thunderbird:2.0.0.15
cpe:/a:mozilla:thunderbird:2.0.0.16
cpe:/a:mozilla:thunderbird:2.0.0.11
...
CWE    1
CWE-200
OVAL    8
oval:org.mitre.oval:def:8021
oval:org.mitre.oval:def:8140
oval:org.secpod.oval:def:600264
oval:org.mitre.oval:def:7950
...

© SecPod Technologies