VDB
CVE-2008-3836
CVE-2008-3836
PUBLISHED
CVSS 7.5 HIGH
feedWriter in Mozilla Firefox before 2.0.0.17 allows remote attackers to execute scripts with chrome privileges via vectors related to feed preview and the (1) elem.doCommand, (2) elem.dispatchEvent, (3) _setTitleText, (4) _setTitleImage, and (5) _initSubscriptionUI functions.
EPSS 2.53% · 84.3th percentile
Risk Scores
CVSS 2.0
7.5
EPSS Score
2.53%
84.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| mozilla | firefox | 0, 0.8, 1.5.0.7 |
Timeline
- Sep 24, 2008 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 13, 2022 EPSS Score
- Sep 5, 2022 EPSS Score
- Dec 20, 2022 EPSS Score
- Feb 3, 2023 EPSS Score
- Feb 11, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 4, 2023 EPSS Score
- May 27, 2023 EPSS Score
- Sep 10, 2023 EPSS Score
References
- SSA:2008-269-01 vendor-advisory
- DSA-1697 vendor-advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=430658 url
- USN-645-2 vendor-advisory
- 31346 vdb
- 32196 third-party-advisory
- DSA-1669 vendor-advisory
- 32042 third-party-advisory
- 33433 third-party-advisory
- 1020914 vdb
- DSA-1649 vendor-advisory
- http://secunia.com/advisories/34501 url
- 32012 third-party-advisory
- firefox-feedwriter-code-execution(45350) vdb
- USN-645-1 vendor-advisory
- 32144 third-party-advisory
- ADV-2009-0977 vdb
- https://bugzilla.mozilla.org/show_bug.cgi?id=360529 url
- SUSE-SA:2008:050 vendor-advisory
- 31984 third-party-advisory
…and 10 more