// For flags

CVE-2008-4066

Mozilla low surrogates stripped from JavaScript before execution

Severity Score

4.3
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

2
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Mozilla Firefox 2.0.0.14, and other versions before 2.0.0.17, allows remote attackers to bypass cross-site scripting (XSS) protection mechanisms and conduct XSS attacks via HTML-escaped low surrogate characters that are ignored by the HTML parser, as demonstrated by a "jav&#56325ascript" sequence, aka "HTML escaped low surrogates bug."

Mozilla Firefox versión 2.0.0.14, y otras versiones anteriores a 2.0.0.17, permiten a los atacantes remotos omitir los mecanismos de protección de cross-site scripting (XSS) y conducir ataques de tipo XSS por medio de caracteres sustitutos bajos con escape de HTML que son ignorados por el analizador HTML, como es demostrado por una secuencia "jav?ascript", también se conoce como "HTML escaped low surrogates bug."

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
None
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2008-09-12 CVE Reserved
  • 2008-09-24 CVE Published
  • 2024-08-07 CVE Updated
  • 2024-08-07 First Exploit
  • 2024-08-25 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (46)
URL Date SRC
URL Date SRC
http://lists.opensuse.org/opensuse-security-announce/2008-10/msg00005.html 2017-09-29
http://secunia.com/advisories/31984 2017-09-29
http://secunia.com/advisories/31985 2017-09-29
http://secunia.com/advisories/32007 2017-09-29
http://secunia.com/advisories/32010 2017-09-29
http://secunia.com/advisories/32012 2017-09-29
http://secunia.com/advisories/32025 2017-09-29
http://secunia.com/advisories/32042 2017-09-29
http://secunia.com/advisories/32044 2017-09-29
http://secunia.com/advisories/32082 2017-09-29
http://secunia.com/advisories/32092 2017-09-29
http://secunia.com/advisories/32144 2017-09-29
http://secunia.com/advisories/32845 2017-09-29
http://secunia.com/advisories/34501 2017-09-29
http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.379422 2017-09-29
http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.405232 2017-09-29
http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.412123 2017-09-29
http://sunsolve.sun.com/search/document.do?assetkey=1-26-256408-1 2017-09-29
http://www.debian.org/security/2008/dsa-1649 2017-09-29
http://www.debian.org/security/2008/dsa-1669 2017-09-29
http://www.mandriva.com/security/advisories?name=MDVSA-2008:205 2017-09-29
http://www.mandriva.com/security/advisories?name=MDVSA-2008:206 2017-09-29
http://www.redhat.com/support/errata/RHSA-2008-0882.html 2017-09-29
http://www.redhat.com/support/errata/RHSA-2008-0908.html 2017-09-29
http://www.ubuntu.com/usn/usn-645-1 2017-09-29
http://www.ubuntu.com/usn/usn-645-2 2017-09-29
http://www.ubuntu.com/usn/usn-647-1 2017-09-29
http://www.vupen.com/english/advisories/2008/2661 2017-09-29
http://www.vupen.com/english/advisories/2009/0977 2017-09-29
https://www.redhat.com/archives/fedora-package-announce/2008-September/msg01384.html 2017-09-29
https://www.redhat.com/archives/fedora-package-announce/2008-September/msg01403.html 2017-09-29
https://access.redhat.com/security/cve/CVE-2008-4066 2008-10-01
https://bugzilla.redhat.com/show_bug.cgi?id=463243 2008-10-01
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Mozilla
Search vendor "Mozilla"
Firefox
Search vendor "Mozilla" for product "Firefox"
2.0.0.14
Search vendor "Mozilla" for product "Firefox" and version "2.0.0.14"
-
Affected
Mozilla
Search vendor "Mozilla"
Firefox
Search vendor "Mozilla" for product "Firefox"
2.0.0.15
Search vendor "Mozilla" for product "Firefox" and version "2.0.0.15"
-
Affected
Mozilla
Search vendor "Mozilla"
Firefox
Search vendor "Mozilla" for product "Firefox"
2.0.0.16
Search vendor "Mozilla" for product "Firefox" and version "2.0.0.16"
-
Affected