// For flags

CVE-2008-0593

Mozilla URL token stealing flaw

Severity Score

4.3
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Gecko-based browsers, including Mozilla Firefox before 2.0.0.12 and SeaMonkey before 1.1.8, modify the .href property of stylesheet DOM nodes to the final URI of a 302 redirect, which might allow remote attackers to bypass the Same Origin Policy and read sensitive information from the original URL, such as with Single-Signon systems.

Los navegadores basados en Gecko, incluyendo Mozilla Firefox versiones anteriores a 2.0.0.12 y SeaMonkey versiones anteriores a 1.1.8, modifican la propiedad .href de los nodos DOM de la hoja de estilo al URI final de un redireccionamiento 302, que podría permitir a los atacantes remotos omitir la Política del Mismo Origen y leer información confidencial de la dirección URL original, como con los sistemas de Single-Signon.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2008-02-05 CVE Reserved
  • 2008-02-08 CVE Published
  • 2024-08-07 CVE Updated
  • 2024-08-21 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (50)
URL Date SRC
URL Date SRC
URL Date SRC
http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00006.html 2018-10-15
http://secunia.com/advisories/28754 2018-10-15
http://secunia.com/advisories/28758 2018-10-15
http://secunia.com/advisories/28766 2018-10-15
http://secunia.com/advisories/28815 2018-10-15
http://secunia.com/advisories/28818 2018-10-15
http://secunia.com/advisories/28839 2018-10-15
http://secunia.com/advisories/28864 2018-10-15
http://secunia.com/advisories/28865 2018-10-15
http://secunia.com/advisories/28877 2018-10-15
http://secunia.com/advisories/28879 2018-10-15
http://secunia.com/advisories/28924 2018-10-15
http://secunia.com/advisories/28939 2018-10-15
http://secunia.com/advisories/28958 2018-10-15
http://secunia.com/advisories/29049 2018-10-15
http://secunia.com/advisories/29086 2018-10-15
http://secunia.com/advisories/29167 2018-10-15
http://secunia.com/advisories/29567 2018-10-15
http://secunia.com/advisories/30327 2018-10-15
http://secunia.com/advisories/30620 2018-10-15
http://sunsolve.sun.com/search/document.do?assetkey=1-26-238492-1 2018-10-15
http://www.debian.org/security/2008/dsa-1484 2018-10-15
http://www.debian.org/security/2008/dsa-1485 2018-10-15
http://www.debian.org/security/2008/dsa-1489 2018-10-15
http://www.debian.org/security/2008/dsa-1506 2018-10-15
http://www.gentoo.org/security/en/glsa/glsa-200805-18.xml 2018-10-15
http://www.mandriva.com/security/advisories?name=MDVSA-2008:048 2018-10-15
http://www.redhat.com/support/errata/RHSA-2008-0103.html 2018-10-15
http://www.redhat.com/support/errata/RHSA-2008-0104.html 2018-10-15
http://www.redhat.com/support/errata/RHSA-2008-0105.html 2018-10-15
http://www.ubuntu.com/usn/usn-576-1 2018-10-15
http://www.vupen.com/english/advisories/2008/0453/references 2018-10-15
http://www.vupen.com/english/advisories/2008/0627/references 2018-10-15
http://www.vupen.com/english/advisories/2008/1793/references 2018-10-15
https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00274.html 2018-10-15
https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00309.html 2018-10-15
https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00381.html 2018-10-15
https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00905.html 2018-10-15
https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00946.html 2018-10-15
https://access.redhat.com/security/cve/CVE-2008-0593 2008-02-08
https://bugzilla.redhat.com/show_bug.cgi?id=431756 2008-02-08
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Mozilla
Search vendor "Mozilla"
Firefox
Search vendor "Mozilla" for product "Firefox"
<= 2.0.0.11
Search vendor "Mozilla" for product "Firefox" and version " <= 2.0.0.11"
-
Affected
Mozilla
Search vendor "Mozilla"
Firefox
Search vendor "Mozilla" for product "Firefox"
0.2
Search vendor "Mozilla" for product "Firefox" and version "0.2"
-
Affected
Mozilla
Search vendor "Mozilla"
Firefox
Search vendor "Mozilla" for product "Firefox"
0.9.2
Search vendor "Mozilla" for product "Firefox" and version "0.9.2"
-
Affected
Mozilla
Search vendor "Mozilla"
Firefox
Search vendor "Mozilla" for product "Firefox"
1.0.2
Search vendor "Mozilla" for product "Firefox" and version "1.0.2"
-
Affected
Mozilla
Search vendor "Mozilla"
Firefox
Search vendor "Mozilla" for product "Firefox"
1.5.0.2
Search vendor "Mozilla" for product "Firefox" and version "1.5.0.2"
-
Affected
Mozilla
Search vendor "Mozilla"
Firefox
Search vendor "Mozilla" for product "Firefox"
1.5.0.12
Search vendor "Mozilla" for product "Firefox" and version "1.5.0.12"
-
Affected
Mozilla
Search vendor "Mozilla"
Firefox
Search vendor "Mozilla" for product "Firefox"
1.5.2
Search vendor "Mozilla" for product "Firefox" and version "1.5.2"
-
Affected
Mozilla
Search vendor "Mozilla"
Firefox
Search vendor "Mozilla" for product "Firefox"
2.0
Search vendor "Mozilla" for product "Firefox" and version "2.0"
-
Affected
Mozilla
Search vendor "Mozilla"
Firefox
Search vendor "Mozilla" for product "Firefox"
2.0.0.1
Search vendor "Mozilla" for product "Firefox" and version "2.0.0.1"
-
Affected
Mozilla
Search vendor "Mozilla"
Firefox
Search vendor "Mozilla" for product "Firefox"
2.0.0.10
Search vendor "Mozilla" for product "Firefox" and version "2.0.0.10"
-
Affected
Mozilla
Search vendor "Mozilla"
Seamonkey
Search vendor "Mozilla" for product "Seamonkey"
*-
Affected
Mozilla
Search vendor "Mozilla"
Seamonkey
Search vendor "Mozilla" for product "Seamonkey"
<= 1.1.17
Search vendor "Mozilla" for product "Seamonkey" and version " <= 1.1.17"
-
Affected
Mozilla
Search vendor "Mozilla"
Seamonkey
Search vendor "Mozilla" for product "Seamonkey"
1.0
Search vendor "Mozilla" for product "Seamonkey" and version "1.0"
-
Affected
Mozilla
Search vendor "Mozilla"
Seamonkey
Search vendor "Mozilla" for product "Seamonkey"
1.0
Search vendor "Mozilla" for product "Seamonkey" and version "1.0"
alpha
Affected
Mozilla
Search vendor "Mozilla"
Seamonkey
Search vendor "Mozilla" for product "Seamonkey"
1.0
Search vendor "Mozilla" for product "Seamonkey" and version "1.0"
beta
Affected
Mozilla
Search vendor "Mozilla"
Seamonkey
Search vendor "Mozilla" for product "Seamonkey"
1.0
Search vendor "Mozilla" for product "Seamonkey" and version "1.0"
dev
Affected
Mozilla
Search vendor "Mozilla"
Seamonkey
Search vendor "Mozilla" for product "Seamonkey"
1.0
Search vendor "Mozilla" for product "Seamonkey" and version "1.0"
alpha
Affected
Mozilla
Search vendor "Mozilla"
Seamonkey
Search vendor "Mozilla" for product "Seamonkey"
1.0
Search vendor "Mozilla" for product "Seamonkey" and version "1.0"
beta
Affected
Mozilla
Search vendor "Mozilla"
Seamonkey
Search vendor "Mozilla" for product "Seamonkey"
1.0.1
Search vendor "Mozilla" for product "Seamonkey" and version "1.0.1"
-
Affected
Mozilla
Search vendor "Mozilla"
Seamonkey
Search vendor "Mozilla" for product "Seamonkey"
1.0.2
Search vendor "Mozilla" for product "Seamonkey" and version "1.0.2"
-
Affected
Mozilla
Search vendor "Mozilla"
Seamonkey
Search vendor "Mozilla" for product "Seamonkey"
1.0.3
Search vendor "Mozilla" for product "Seamonkey" and version "1.0.3"
-
Affected
Mozilla
Search vendor "Mozilla"
Seamonkey
Search vendor "Mozilla" for product "Seamonkey"
1.0.4
Search vendor "Mozilla" for product "Seamonkey" and version "1.0.4"
-
Affected
Mozilla
Search vendor "Mozilla"
Seamonkey
Search vendor "Mozilla" for product "Seamonkey"
1.0.5
Search vendor "Mozilla" for product "Seamonkey" and version "1.0.5"
-
Affected
Mozilla
Search vendor "Mozilla"
Seamonkey
Search vendor "Mozilla" for product "Seamonkey"
1.0.6
Search vendor "Mozilla" for product "Seamonkey" and version "1.0.6"
-
Affected
Mozilla
Search vendor "Mozilla"
Seamonkey
Search vendor "Mozilla" for product "Seamonkey"
1.0.7
Search vendor "Mozilla" for product "Seamonkey" and version "1.0.7"
-
Affected
Mozilla
Search vendor "Mozilla"
Seamonkey
Search vendor "Mozilla" for product "Seamonkey"
1.0.8
Search vendor "Mozilla" for product "Seamonkey" and version "1.0.8"
-
Affected
Mozilla
Search vendor "Mozilla"
Seamonkey
Search vendor "Mozilla" for product "Seamonkey"
1.0.9
Search vendor "Mozilla" for product "Seamonkey" and version "1.0.9"
-
Affected
Mozilla
Search vendor "Mozilla"
Seamonkey
Search vendor "Mozilla" for product "Seamonkey"
1.0.99
Search vendor "Mozilla" for product "Seamonkey" and version "1.0.99"
-
Affected
Mozilla
Search vendor "Mozilla"
Seamonkey
Search vendor "Mozilla" for product "Seamonkey"
1.1
Search vendor "Mozilla" for product "Seamonkey" and version "1.1"
-
Affected
Mozilla
Search vendor "Mozilla"
Seamonkey
Search vendor "Mozilla" for product "Seamonkey"
1.1.1
Search vendor "Mozilla" for product "Seamonkey" and version "1.1.1"
-
Affected
Mozilla
Search vendor "Mozilla"
Seamonkey
Search vendor "Mozilla" for product "Seamonkey"
1.1.2
Search vendor "Mozilla" for product "Seamonkey" and version "1.1.2"
-
Affected
Mozilla
Search vendor "Mozilla"
Seamonkey
Search vendor "Mozilla" for product "Seamonkey"
1.1.10
Search vendor "Mozilla" for product "Seamonkey" and version "1.1.10"
-
Affected
Mozilla
Search vendor "Mozilla"
Seamonkey
Search vendor "Mozilla" for product "Seamonkey"
1.1.11
Search vendor "Mozilla" for product "Seamonkey" and version "1.1.11"
-
Affected
Mozilla
Search vendor "Mozilla"
Seamonkey
Search vendor "Mozilla" for product "Seamonkey"
1.1.12
Search vendor "Mozilla" for product "Seamonkey" and version "1.1.12"
-
Affected
Mozilla
Search vendor "Mozilla"
Seamonkey
Search vendor "Mozilla" for product "Seamonkey"
1.1.13
Search vendor "Mozilla" for product "Seamonkey" and version "1.1.13"
-
Affected
Mozilla
Search vendor "Mozilla"
Seamonkey
Search vendor "Mozilla" for product "Seamonkey"
1.1.14
Search vendor "Mozilla" for product "Seamonkey" and version "1.1.14"
-
Affected
Mozilla
Search vendor "Mozilla"
Seamonkey
Search vendor "Mozilla" for product "Seamonkey"
1.1.15
Search vendor "Mozilla" for product "Seamonkey" and version "1.1.15"
-
Affected
Mozilla
Search vendor "Mozilla"
Seamonkey
Search vendor "Mozilla" for product "Seamonkey"
1.1.16
Search vendor "Mozilla" for product "Seamonkey" and version "1.1.16"
-
Affected