CVE-2008-4066

Description

Mozilla Firefox 2.0.0.14, and other versions before 2.0.0.17, allows remote attackers to bypass cross-site scripting (XSS) protection mechanisms and conduct XSS attacks via HTML-escaped low surrogate characters that are ignored by the HTML parser, as demonstrated by a java ascript sequence, aka HTML escaped low surrogates bug.

Risk Information

Base Score
6.1
MODERATE
Vector
AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS Score
Exploitation Probability
1.204

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities affected in Mozilla Firefox (x64) 2.0.0.16Windows
Multiple vulnerabilities affected in Mozilla_Firefox 2.0.0.16Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 2.0.0.14Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 2.0.0.15Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 2.0.0.16Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 2.0.0.14Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 2.0.0.15Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 2.0.0.16Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-343016Mozilla Firefox (x64) (132.0.2)
PATCH-343015Mozilla Firefox (132.0.2)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234