Security Advisory

CVE-2008-0415

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2008-02-08 21:00:00
Last updated 2024-08-07 07:46:54
Assigner redhat
CVSS score not scored
State PUBLISHED

Description

Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8 allows remote attackers to execute script outside of the sandbox and conduct cross-site scripting (XSS) attacks via multiple vectors including the XMLDocument.load function, aka "JavaScript privilege escalation bugs."