CVE-2008-3836 PUBLISHED CVSS 7.5 HIGH

feedWriter in Mozilla Firefox before 2.0.0.17 allows remote attackers to execute scripts with chrome privileges via vectors related to feed preview and the (1) elem.doCommand, (2) elem.dispatchEvent, (3) _setTitleText, (4) _setTitleImage, and (5) _initSubscriptionUI functions.

EPSS 2.94% · 86.3th percentile

Risk Scores

CVSS v2.0
7.5
EPSS Score
2.94%
86.3th percentile

Affected Products

VendorProductVersions
n/an/an/a
mozillafirefox0, 0.8, 0.9

Timeline

References

…and 10 more

Open in Interactive Console →