CVE-2008-2803
Description
The mozIJSSubScriptLoader.LoadScript function in Mozilla Firefox before 2.0.0.15, Thunderbird 2.0.0.14 and earlier, and SeaMonkey before 1.1.10 does not apply XPCNativeWrappers to scripts loaded from (1) file: URIs, (2) data: URIs, or (3) certain non-canonical chrome: URIs, which allows remote attackers to execute arbitrary code via vectors involving third-party add-ons.
Risk Information
Base Score
9.8
MODERATE
Vector
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
6.393
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Mozilla Firefox (63.0) | Windows |
| Mozilla Firefox (x64) (63.0) | Windows |
| Multiple Vulnerabilities are affected in Mozilla Thunderbird 2.0.0.14 | Windows |
| Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 2.0 | Windows |
| Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 2.0.0.1 | Windows |
| Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 2.0.0.10 | Windows |
| Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 2.0.0.11 | Windows |
| Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 2.0.0.12 | Windows |
| Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 2.0.0.13 | Windows |
| Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 2.0.0.14 | Windows |
| Multiple Vulnerabilities are affected in Mozilla_Firefox 2.0 | Windows |
| Multiple Vulnerabilities are affected in Mozilla_Firefox 2.0.0.1 | Windows |
| Multiple Vulnerabilities are affected in Mozilla_Firefox 2.0.0.10 | Windows |
| Multiple Vulnerabilities are affected in Mozilla_Firefox 2.0.0.11 | Windows |
| Multiple Vulnerabilities are affected in Mozilla_Firefox 2.0.0.12 | Windows |
| Multiple Vulnerabilities are affected in Mozilla_Firefox 2.0.0.13 | Windows |
| Multiple Vulnerabilities are affected in Mozilla_Firefox 2.0.0.14 | Windows |
| Multiple Vulnerabilities are affected in Mozilla Thunderbird 2.0.0.0 | Windows |
| Multiple Vulnerabilities are affected in Mozilla Thunderbird 2.0.0.12 | Windows |
| Multiple Vulnerabilities are affected in Mozilla Thunderbird 2.0.0.4 | Windows |
| Multiple Vulnerabilities are affected in Mozilla Thunderbird 2.0.0.5 | Windows |
| Multiple Vulnerabilities are affected in Mozilla Thunderbird 2.0.0.6 | Windows |
| Multiple Vulnerabilities are affected in Mozilla Thunderbird 2.0.0.9 | Windows |
| Multiple Vulnerabilities are affected in Mozilla Thunderbird 2.0.0.1 | Windows |
| Multiple Vulnerabilities are affected in Mozilla Thunderbird 2.0.0.2 | Windows |
| Multiple Vulnerabilities are affected in Mozilla Thunderbird 2.0.0.3 | Windows |
| Multiple Vulnerabilities are affected in Mozilla Thunderbird 2.0.0.8 | Windows |
| Multiple Vulnerabilities are affected in Mozilla Thunderbird 2.0.0.11 | Windows |
| Multiple Vulnerabilities are affected in Mozilla Thunderbird 2.0.0.13 | Windows |
| Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 2.0.0.2 | Windows |
| Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 2.0.0.3 | Windows |
| Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 2.0.0.4 | Windows |
| Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 2.0.0.5 | Windows |
| Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 2.0.0.6 | Windows |
| Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 2.0.0.7 | Windows |
| Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 2.0.0.8 | Windows |
| Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 2.0.0.9 | Windows |
| Multiple Vulnerabilities are affected in Mozilla_Firefox 2.0.0.2 | Windows |
| Multiple Vulnerabilities are affected in Mozilla_Firefox 2.0.0.3 | Windows |
| Multiple Vulnerabilities are affected in Mozilla_Firefox 2.0.0.4 | Windows |
| Multiple Vulnerabilities are affected in Mozilla_Firefox 2.0.0.5 | Windows |
| Multiple Vulnerabilities are affected in Mozilla_Firefox 2.0.0.6 | Windows |
| Multiple Vulnerabilities are affected in Mozilla_Firefox 2.0.0.7 | Windows |
| Multiple Vulnerabilities are affected in Mozilla_Firefox 2.0.0.8 | Windows |
| Multiple Vulnerabilities are affected in Mozilla_Firefox 2.0.0.9 | Windows |
| Multiple vulnerabilities are fixed in Mozilla Firefox For Mac 2.0.0.15 | Mac |
Patch Details
Click to see the patches provided by ManageEngine for this CVE
| Patch ID | Patch Description |
|---|---|
| PATCH-308288 | Mozilla Firefox (63.0) |
| PATCH-308291 | Mozilla Firefox (x64) (63.0) |
| PATCH-315938 | Mozilla Thunderbird (68.12.0) |
| PATCH-613630 | Mozilla Firefox For Mac (147.0.4) |
References
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234