CVE Vulnerabilities

CVE-2008-3835

Published: Sep 24, 2008 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The nsXMLDocument::OnChannelRedirect function in Mozilla Firefox before 2.0.0.17, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows remote attackers to bypass the Same Origin Policy and execute arbitrary JavaScript code via unknown vectors.

Affected Software

NameVendorStart VersionEnd Version
FirefoxMozilla*2.0.0.16 (including)
FirefoxMozilla0.8 (including)0.8 (including)
FirefoxMozilla0.9 (including)0.9 (including)
FirefoxMozilla0.9-rc (including)0.9-rc (including)
FirefoxMozilla0.9.1 (including)0.9.1 (including)
FirefoxMozilla0.9.2 (including)0.9.2 (including)
FirefoxMozilla0.9.3 (including)0.9.3 (including)
FirefoxMozilla0.9_rc (including)0.9_rc (including)
FirefoxMozilla0.10 (including)0.10 (including)
FirefoxMozilla0.10.1 (including)0.10.1 (including)
FirefoxMozilla1.0 (including)1.0 (including)
FirefoxMozilla1.0.1 (including)1.0.1 (including)
FirefoxMozilla1.0.2 (including)1.0.2 (including)
FirefoxMozilla1.0.3 (including)1.0.3 (including)
FirefoxMozilla1.0.4 (including)1.0.4 (including)
FirefoxMozilla1.0.5 (including)1.0.5 (including)
FirefoxMozilla1.0.6 (including)1.0.6 (including)
FirefoxMozilla1.0.7 (including)1.0.7 (including)
FirefoxMozilla1.0.8 (including)1.0.8 (including)
FirefoxMozilla1.5 (including)1.5 (including)
FirefoxMozilla1.5-beta1 (including)1.5-beta1 (including)
FirefoxMozilla1.5-beta2 (including)1.5-beta2 (including)
FirefoxMozilla1.5.0.1 (including)1.5.0.1 (including)
FirefoxMozilla1.5.0.2 (including)1.5.0.2 (including)
FirefoxMozilla1.5.0.3 (including)1.5.0.3 (including)
FirefoxMozilla1.5.0.4 (including)1.5.0.4 (including)
FirefoxMozilla1.5.0.5 (including)1.5.0.5 (including)
FirefoxMozilla1.5.0.6 (including)1.5.0.6 (including)
FirefoxMozilla1.5.0.7 (including)1.5.0.7 (including)
FirefoxMozilla1.5.0.8 (including)1.5.0.8 (including)
FirefoxMozilla1.5.0.9 (including)1.5.0.9 (including)
FirefoxMozilla1.5.0.10 (including)1.5.0.10 (including)
FirefoxMozilla1.5.0.11 (including)1.5.0.11 (including)
FirefoxMozilla1.5.0.12 (including)1.5.0.12 (including)
FirefoxMozilla1.5.1 (including)1.5.1 (including)
FirefoxMozilla1.5.2 (including)1.5.2 (including)
FirefoxMozilla1.5.3 (including)1.5.3 (including)
FirefoxMozilla1.5.4 (including)1.5.4 (including)
FirefoxMozilla1.5.5 (including)1.5.5 (including)
FirefoxMozilla1.5.6 (including)1.5.6 (including)
FirefoxMozilla1.5.7 (including)1.5.7 (including)
FirefoxMozilla1.5.8 (including)1.5.8 (including)
FirefoxMozilla1.8 (including)1.8 (including)
FirefoxMozilla2.0 (including)2.0 (including)
FirefoxMozilla2.0.0.1 (including)2.0.0.1 (including)
FirefoxMozilla2.0.0.10 (including)2.0.0.10 (including)
FirefoxMozilla2.0.0.11 (including)2.0.0.11 (including)
FirefoxMozilla2.0.0.12 (including)2.0.0.12 (including)
FirefoxMozilla2.0.0.13 (including)2.0.0.13 (including)
FirefoxMozilla2.0.0.14 (including)2.0.0.14 (including)
FirefoxMozilla2.0.0.15 (including)2.0.0.15 (including)
SeamonkeyMozilla**
SeamonkeyMozilla*1.1.11 (including)
SeamonkeyMozilla1.0 (including)1.0 (including)
SeamonkeyMozilla1.0-beta (including)1.0-beta (including)
SeamonkeyMozilla1.0.1 (including)1.0.1 (including)
SeamonkeyMozilla1.0.2 (including)1.0.2 (including)
SeamonkeyMozilla1.0.3 (including)1.0.3 (including)
SeamonkeyMozilla1.0.4 (including)1.0.4 (including)
SeamonkeyMozilla1.0.5 (including)1.0.5 (including)
SeamonkeyMozilla1.0.6 (including)1.0.6 (including)
SeamonkeyMozilla1.0.7 (including)1.0.7 (including)
SeamonkeyMozilla1.0.8 (including)1.0.8 (including)
SeamonkeyMozilla1.0.9 (including)1.0.9 (including)
SeamonkeyMozilla1.0.99 (including)1.0.99 (including)
SeamonkeyMozilla1.1 (including)1.1 (including)
SeamonkeyMozilla1.1.1 (including)1.1.1 (including)
SeamonkeyMozilla1.1.10 (including)1.1.10 (including)
ThunderbirdMozilla**
ThunderbirdMozilla*2.0.0.16 (including)
ThunderbirdMozilla0.1 (including)0.1 (including)
ThunderbirdMozilla0.2 (including)0.2 (including)
ThunderbirdMozilla0.3 (including)0.3 (including)
ThunderbirdMozilla0.4 (including)0.4 (including)
ThunderbirdMozilla0.5 (including)0.5 (including)
ThunderbirdMozilla0.6 (including)0.6 (including)
ThunderbirdMozilla0.7 (including)0.7 (including)
ThunderbirdMozilla0.7.1 (including)0.7.1 (including)
ThunderbirdMozilla0.7.2 (including)0.7.2 (including)
ThunderbirdMozilla0.7.3 (including)0.7.3 (including)
ThunderbirdMozilla0.8 (including)0.8 (including)
ThunderbirdMozilla0.9 (including)0.9 (including)
ThunderbirdMozilla1.0 (including)1.0 (including)
ThunderbirdMozilla1.0.1 (including)1.0.1 (including)
ThunderbirdMozilla1.0.2 (including)1.0.2 (including)
ThunderbirdMozilla1.0.3 (including)1.0.3 (including)
ThunderbirdMozilla1.0.4 (including)1.0.4 (including)
ThunderbirdMozilla1.0.5 (including)1.0.5 (including)
ThunderbirdMozilla1.0.5-beta (including)1.0.5-beta (including)
ThunderbirdMozilla1.0.6 (including)1.0.6 (including)
ThunderbirdMozilla1.0.7 (including)1.0.7 (including)
ThunderbirdMozilla1.0.8 (including)1.0.8 (including)
ThunderbirdMozilla1.5 (including)1.5 (including)
ThunderbirdMozilla1.5-beta2 (including)1.5-beta2 (including)
ThunderbirdMozilla1.5.0.1 (including)1.5.0.1 (including)
ThunderbirdMozilla1.5.0.2 (including)1.5.0.2 (including)
ThunderbirdMozilla1.5.0.3 (including)1.5.0.3 (including)
ThunderbirdMozilla1.5.0.4 (including)1.5.0.4 (including)
ThunderbirdMozilla1.5.0.6 (including)1.5.0.6 (including)
ThunderbirdMozilla1.5.0.7 (including)1.5.0.7 (including)
ThunderbirdMozilla1.5.0.8 (including)1.5.0.8 (including)
ThunderbirdMozilla1.5.0.9 (including)1.5.0.9 (including)
ThunderbirdMozilla1.5.0.10 (including)1.5.0.10 (including)
ThunderbirdMozilla1.5.0.11 (including)1.5.0.11 (including)
ThunderbirdMozilla1.5.1 (including)1.5.1 (including)
ThunderbirdMozilla1.5.2 (including)1.5.2 (including)
ThunderbirdMozilla1.7.1 (including)1.7.1 (including)
ThunderbirdMozilla1.7.3 (including)1.7.3 (including)
ThunderbirdMozilla2.0.0.0 (including)2.0.0.0 (including)
ThunderbirdMozilla2.0.0.1 (including)2.0.0.1 (including)
ThunderbirdMozilla2.0.0.2 (including)2.0.0.2 (including)
ThunderbirdMozilla2.0.0.3 (including)2.0.0.3 (including)
ThunderbirdMozilla2.0.0.4 (including)2.0.0.4 (including)
ThunderbirdMozilla2.0.0.5 (including)2.0.0.5 (including)
ThunderbirdMozilla2.0.0.6 (including)2.0.0.6 (including)
ThunderbirdMozilla2.0.0.8 (including)2.0.0.8 (including)
ThunderbirdMozilla2.0.0.9 (including)2.0.0.9 (including)
ThunderbirdMozilla2.0.0.11 (including)2.0.0.11 (including)
ThunderbirdMozilla2.0.0.12 (including)2.0.0.12 (including)
ThunderbirdMozilla2.0.0.13 (including)2.0.0.13 (including)
ThunderbirdMozilla2.0.0.14 (including)2.0.0.14 (including)
ThunderbirdMozilla2.0.0.15 (including)2.0.0.15 (including)
ThunderbirdMozilla2.0_.4 (including)2.0_.4 (including)
ThunderbirdMozilla2.0_.5 (including)2.0_.5 (including)
ThunderbirdMozilla2.0_.6 (including)2.0_.6 (including)
ThunderbirdMozilla2.0_.9 (including)2.0_.9 (including)
ThunderbirdMozilla2.0_.12 (including)2.0_.12 (including)
ThunderbirdMozilla2.0_.13 (including)2.0_.13 (including)
ThunderbirdMozilla2.0_.14 (including)2.0_.14 (including)
ThunderbirdMozilla2.0_8 (including)2.0_8 (including)
Red Hat Enterprise Linux 2.1RedHatseamonkey-0:1.0.9-0.20.el2*
Red Hat Enterprise Linux 3RedHatseamonkey-0:1.0.9-0.24.el3*
Red Hat Enterprise Linux 4RedHatdevhelp-0:0.10-0.10.el4*
Red Hat Enterprise Linux 4RedHatseamonkey-0:1.0.9-26.el4*
Red Hat Enterprise Linux 4RedHatthunderbird-0:1.5.0.12-16.el4*
Red Hat Enterprise Linux 5RedHatthunderbird-0:2.0.0.17-1.el5*
FirefoxUbuntudapper*
FirefoxUbuntudevel*
FirefoxUbuntufeisty*
FirefoxUbuntugutsy*
FirefoxUbuntuhardy*
FirefoxUbuntulucid*
FirefoxUbuntumaverick*
FirefoxUbuntunatty*
FirefoxUbuntuupstream*
Firefox-3.0Ubuntugutsy*
Firefox-3.0Ubuntuhardy*
Firefox-3.0Ubuntuintrepid*
Firefox-3.0Ubuntujaunty*
Firefox-3.0Ubuntuupstream*
IceapeUbuntugutsy*
Mozilla-thunderbirdUbuntudapper*
Mozilla-thunderbirdUbuntufeisty*
SeamonkeyUbuntudevel*
SeamonkeyUbuntuhardy*
SeamonkeyUbuntuintrepid*
SeamonkeyUbuntujaunty*
SeamonkeyUbuntukarmic*
SeamonkeyUbuntulucid*
SeamonkeyUbuntumaverick*
SeamonkeyUbuntunatty*
SeamonkeyUbuntuupstream*
ThunderbirdUbuntudevel*
ThunderbirdUbuntugutsy*
ThunderbirdUbuntuhardy*
ThunderbirdUbuntuintrepid*
ThunderbirdUbuntujaunty*
ThunderbirdUbuntukarmic*
ThunderbirdUbuntulucid*
ThunderbirdUbuntumaverick*
ThunderbirdUbuntunatty*
ThunderbirdUbuntuupstream*
XulrunnerUbuntufeisty*
XulrunnerUbuntugutsy*
XulrunnerUbuntuhardy*
XulrunnerUbuntuintrepid*
XulrunnerUbuntujaunty*
XulrunnerUbuntukarmic*
Xulrunner-1.9Ubuntugutsy*
Xulrunner-1.9Ubuntuhardy*
Xulrunner-1.9Ubuntuintrepid*
Xulrunner-1.9Ubuntujaunty*
Xulrunner-1.9Ubuntuupstream*

References