CVE Vulnerabilities

CVE-2008-5506

Published: Dec 17, 2008 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to bypass the same origin policy by causing the browser to issue an XMLHttpRequest to an attacker-controlled resource that uses a 302 redirect to a resource in a different domain, then reading content from the response, aka response disclosure.

Affected Software

NameVendorStart VersionEnd Version
FirefoxMozilla2.0 (including)2.0.0.19 (excluding)
FirefoxMozilla3.0 (including)3.0.5 (excluding)
SeamonkeyMozilla1.0 (including)1.1.14 (excluding)
ThunderbirdMozilla2.0 (including)2.0.0.19 (excluding)
Red Hat Enterprise Linux 2.1RedHatseamonkey-0:1.0.9-0.25.el2*
Red Hat Enterprise Linux 3RedHatseamonkey-0:1.0.9-0.29.el3*
Red Hat Enterprise Linux 4RedHatfirefox-0:3.0.5-1.el4*
Red Hat Enterprise Linux 4RedHatnspr-0:4.7.3-1.el4*
Red Hat Enterprise Linux 4RedHatnss-0:3.12.2.0-1.el4*
Red Hat Enterprise Linux 4RedHatseamonkey-0:1.0.9-32.el4*
Red Hat Enterprise Linux 4RedHatthunderbird-0:1.5.0.12-18.el4*
Red Hat Enterprise Linux 5RedHatfirefox-0:3.0.5-1.el5_2*
Red Hat Enterprise Linux 5RedHatnspr-0:4.7.3-2.el5*
Red Hat Enterprise Linux 5RedHatnss-0:3.12.2.0-2.el5*
Red Hat Enterprise Linux 5RedHatxulrunner-0:1.9.0.5-1.el5_2*
Red Hat Enterprise Linux 5RedHatthunderbird-0:2.0.0.19-1.el5_2*
FirefoxUbuntudapper*
FirefoxUbuntudevel*
FirefoxUbuntugutsy*
FirefoxUbuntuhardy*
FirefoxUbuntulucid*
FirefoxUbuntumaverick*
FirefoxUbuntunatty*
FirefoxUbuntuupstream*
Firefox-3.0Ubuntugutsy*
Firefox-3.0Ubuntuhardy*
Firefox-3.0Ubuntuintrepid*
Firefox-3.0Ubuntujaunty*
Firefox-3.0Ubuntuupstream*
IceapeUbuntugutsy*
IceapeUbuntuupstream*
Mozilla-thunderbirdUbuntudapper*
SeamonkeyUbuntudevel*
SeamonkeyUbuntuhardy*
SeamonkeyUbuntuintrepid*
SeamonkeyUbuntujaunty*
SeamonkeyUbuntukarmic*
SeamonkeyUbuntulucid*
SeamonkeyUbuntumaverick*
SeamonkeyUbuntunatty*
SeamonkeyUbuntuupstream*
ThunderbirdUbuntudevel*
ThunderbirdUbuntugutsy*
ThunderbirdUbuntuhardy*
ThunderbirdUbuntuintrepid*
ThunderbirdUbuntujaunty*
ThunderbirdUbuntukarmic*
ThunderbirdUbuntulucid*
ThunderbirdUbuntumaverick*
ThunderbirdUbuntunatty*
ThunderbirdUbuntuupstream*
XulrunnerUbuntugutsy*
XulrunnerUbuntuhardy*
XulrunnerUbuntuintrepid*
XulrunnerUbuntujaunty*
XulrunnerUbuntukarmic*
Xulrunner-1.9Ubuntugutsy*
Xulrunner-1.9Ubuntuhardy*
Xulrunner-1.9Ubuntuintrepid*
Xulrunner-1.9Ubuntujaunty*

References