FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2008-5504

This CVE name corresponds to:

Entered Topic
2008-12-19 mozilla -- multiple vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2008-5504
Phase Assigned(20081212)

Description

Mozilla Firefox 2.x before 2.0.0.19 allows remote attackers to run arbitrary JavaScript with chrome privileges via vectors related to the feed preview, a different vulnerability than CVE-2008-3836.

References

Source Reference
MISC https://bugzilla.mozilla.org/show_bug.cgi?id=453526
CONFIRM http://www.mozilla.org/security/announce/2008/mfsa2008-62.html
DEBIAN DSA-1707
MANDRIVA MDVSA-2008:244
REDHAT RHSA-2008:1037
SUNALERT 256408
UBUNTU USN-690-2
BID 32882
OVAL oval:org.mitre.oval:def:10781
SECTRACK 1021422
SECUNIA 33231
SECUNIA 33523
SECUNIA 33184
SECUNIA 33189
SECUNIA 34501
VUPEN ADV-2009-0977
XF firefox-feedpreview-code-execution(47410)