CVE-2008-5505

Mozilla Firefox 3.x before 3.0.5 allows remote attackers to bypass intended privacy restrictions by using the persist attribute in an XUL element to create and access data entities that are similar to cookies.
References
Link Resource
http://secunia.com/advisories/33188
http://secunia.com/advisories/33203
http://secunia.com/advisories/33216
http://secunia.com/advisories/34501
http://sunsolve.sun.com/search/document.do?assetkey=1-26-256408-1
http://www.mandriva.com/security/advisories?name=MDVSA-2008:245
http://www.mozilla.org/security/announce/2008/mfsa2008-63.html Vendor Advisory
http://www.redhat.com/support/errata/RHSA-2008-1036.html
http://www.securityfocus.com/bid/32882
http://www.securitytracker.com/id?1021428
http://www.vupen.com/english/advisories/2009/0977
https://bugzilla.mozilla.org/show_bug.cgi?id=295994
https://exchange.xforce.ibmcloud.com/vulnerabilities/47411
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10443
https://usn.ubuntu.com/690-1/
http://secunia.com/advisories/33188
http://secunia.com/advisories/33203
http://secunia.com/advisories/33216
http://secunia.com/advisories/34501
http://sunsolve.sun.com/search/document.do?assetkey=1-26-256408-1
http://www.mandriva.com/security/advisories?name=MDVSA-2008:245
http://www.mozilla.org/security/announce/2008/mfsa2008-63.html Vendor Advisory
http://www.redhat.com/support/errata/RHSA-2008-1036.html
http://www.securityfocus.com/bid/32882
http://www.securitytracker.com/id?1021428
http://www.vupen.com/english/advisories/2009/0977
https://bugzilla.mozilla.org/show_bug.cgi?id=295994
https://exchange.xforce.ibmcloud.com/vulnerabilities/47411
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10443
https://usn.ubuntu.com/690-1/
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:3.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:3.0.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:3.0.2:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:3.0.3:*:*:*:*:*:*:*

History

21 Nov 2024, 00:54

Type Values Removed Values Added
References () http://secunia.com/advisories/33188 - () http://secunia.com/advisories/33188 -
References () http://secunia.com/advisories/33203 - () http://secunia.com/advisories/33203 -
References () http://secunia.com/advisories/33216 - () http://secunia.com/advisories/33216 -
References () http://secunia.com/advisories/34501 - () http://secunia.com/advisories/34501 -
References () http://sunsolve.sun.com/search/document.do?assetkey=1-26-256408-1 - () http://sunsolve.sun.com/search/document.do?assetkey=1-26-256408-1 -
References () http://www.mandriva.com/security/advisories?name=MDVSA-2008:245 - () http://www.mandriva.com/security/advisories?name=MDVSA-2008:245 -
References () http://www.mozilla.org/security/announce/2008/mfsa2008-63.html - Vendor Advisory () http://www.mozilla.org/security/announce/2008/mfsa2008-63.html - Vendor Advisory
References () http://www.redhat.com/support/errata/RHSA-2008-1036.html - () http://www.redhat.com/support/errata/RHSA-2008-1036.html -
References () http://www.securityfocus.com/bid/32882 - () http://www.securityfocus.com/bid/32882 -
References () http://www.securitytracker.com/id?1021428 - () http://www.securitytracker.com/id?1021428 -
References () http://www.vupen.com/english/advisories/2009/0977 - () http://www.vupen.com/english/advisories/2009/0977 -
References () https://bugzilla.mozilla.org/show_bug.cgi?id=295994 - () https://bugzilla.mozilla.org/show_bug.cgi?id=295994 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/47411 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/47411 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10443 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10443 -
References () https://usn.ubuntu.com/690-1/ - () https://usn.ubuntu.com/690-1/ -

Information

Published : 2008-12-17 23:30

Updated : 2024-11-21 00:54


NVD link : CVE-2008-5505

Mitre link : CVE-2008-5505

CVE.ORG link : CVE-2008-5505


JSON object : View

Products Affected

mozilla

  • firefox
CWE
CWE-264

Permissions, Privileges, and Access Controls