{"cves":[{"id":"CVE-2008-5618","published":"2008-12-17T02:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nimudp in rsyslog 4.x before 4.1.2, 3.21 before 3.21.9 beta, and 3.20 before\n3.20.2 generates a message even when it is sent by an unauthorized sender,\nwhich allows remote attackers to cause a denial of service (disk\nconsumption) via a large number of spurious messages.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=510906","https://www.cve.org/CVERecord?id=CVE-2008-5618"],"bugs":[""],"patches":{"rsyslog":[]},"tags":{},"packages":[{"name":"rsyslog","source":"https://ubuntu.com/security/cve?package=rsyslog","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=rsyslog","debian":"https://tracker.debian.org/pkg/rsyslog","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"3.18.6-2","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"3.18.6-2","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"3.18.6-2","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"3.18.6-2","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"3.18.6-2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.18.6-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-5617","published":"2008-12-17T02:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe ACL handling in rsyslog 3.12.1 to 3.20.0, 4.1.0, and 4.1.1 does not\nfollow $AllowedSender directive, which allows remote attackers to bypass\nintended access restrictions and spoof log messages or create a large\nnumber of spurious messages.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508027","https://www.cve.org/CVERecord?id=CVE-2008-5617"],"bugs":[""],"patches":{"rsyslog":[]},"tags":{},"packages":[{"name":"rsyslog","source":"https://ubuntu.com/security/cve?package=rsyslog","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=rsyslog","debian":"https://tracker.debian.org/pkg/rsyslog","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"3.18.6-2","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"3.18.6-2","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"3.18.6-2","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"3.18.6-2","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"3.18.6-2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.18.6-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-5081","published":"2008-12-17T02:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe originates_from_local_legacy_unicast_socket function\n(avahi-core/server.c) in avahi-daemon in Avahi before 0.6.24 allows remote\nattackers to cause a denial of service (crash) via a crafted mDNS packet\nwith a source port of 0, which triggers an assertion failure.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-696-1","https://www.cve.org/CVERecord?id=CVE-2008-5081"],"bugs":[""],"patches":{"avahi":[]},"tags":{},"packages":[{"name":"avahi","source":"https://ubuntu.com/security/cve?package=avahi","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=avahi","debian":"https://tracker.debian.org/pkg/avahi","statuses":[{"release_codename":"upstream","status":"released","description":"0.6.24","component":null,"pocket":"security"},{"release_codename":"dapper","status":"released","description":"0.6.10-0ubuntu3.5","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"0.6.20-2ubuntu3.4","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"0.6.22-2ubuntu4.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"0.6.23-2ubuntu2.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-696-1"],"notices":[{"id":"USN-696-1","title":"Avahi vulnerabilities","summary":"Avahi vulnerabilities","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.\n","references":[],"published":"2008-12-18T22:24:52.421904","description":"Emanuele Aina discovered that Avahi did not properly validate its input when\nprocessing data over D-Bus. A local attacker could send an empty TXT message\nvia D-Bus and cause a denial of service (failed assertion). This issue only\naffected Ubuntu 6.06 LTS. (CVE-2007-3372)\n\nHugo Dias discovered that Avahi did not properly verify its input when\nprocessing mDNS packets. A remote attacker could send a crafted mDNS packet\nand cause a denial of service (assertion failure). (CVE-2008-5081)\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"avahi","version":"0.6.20-2ubuntu3.4","description":"","is_source":true},{"name":"avahi-daemon","version":"0.6.20-2ubuntu3.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/avahi","version_link":"https://launchpad.net/ubuntu/+source/avahi/0.6.20-2ubuntu3.4"}],"dapper":[{"name":"avahi","version":"0.6.10-0ubuntu3.5","description":"","is_source":true},{"name":"avahi-daemon","version":"0.6.10-0ubuntu3.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/avahi","version_link":"https://launchpad.net/ubuntu/+source/avahi/0.6.10-0ubuntu3.5"}],"intrepid":[{"name":"avahi","version":"0.6.23-2ubuntu2.1","description":"","is_source":true},{"name":"avahi-daemon","version":"0.6.23-2ubuntu2.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/avahi","version_link":"https://launchpad.net/ubuntu/+source/avahi/0.6.23-2ubuntu2.1"}],"hardy":[{"name":"avahi","version":"0.6.22-2ubuntu4.1","description":"","is_source":true},{"name":"avahi-daemon","version":"0.6.22-2ubuntu4.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/avahi","version_link":"https://launchpad.net/ubuntu/+source/avahi/0.6.22-2ubuntu4.1"}]},"type":"USN","cves_ids":["CVE-2007-3372","CVE-2008-5081"]}]},{"id":"CVE-2008-5616","published":"2008-12-17T01:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nStack-based buffer overflow in the demux_open_vqf function in\nlibmpdemux/demux_vqf.c in MPlayer 1.0 rc2 before r28150 allows remote\nattackers to execute arbitrary code via a malformed TwinVQ file.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508803","https://www.cve.org/CVERecord?id=CVE-2008-5616"],"bugs":[""],"patches":{"mplayer":[]},"tags":{},"packages":[{"name":"mplayer","source":"https://ubuntu.com/security/cve?package=mplayer","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mplayer","debian":"https://tracker.debian.org/pkg/mplayer","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"2:1.0~rc3+svn20090426-1ubuntu4","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"2:1.0~rc3+svn20090426-1ubuntu4","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"2:1.0~rc3+svn20090426-1ubuntu4","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"2:1.0~rc3+svn20090426-1ubuntu4","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"2:1.0~rc3+svn20090426-1ubuntu4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.0~rc2-19","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-5624","published":"2008-12-17T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nPHP 5 before 5.2.7 does not properly initialize the page_uid and page_gid\nglobal variables for use by the SAPI php_getuid function, which allows\ncontext-dependent attackers to bypass safe_mode restrictions via variable\nsettings that are intended to be restricted to root, as demonstrated by a\nsetting of /etc for the error_log variable.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"the second upstream patch is for apache 1.x sapi\napache 1.x is still in Dapper, so we better include it"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508021","http://www.php.net/ChangeLog-5.php#5.2.7","https://ubuntu.com/security/notices/USN-720-1","https://www.cve.org/CVERecord?id=CVE-2008-5624"],"bugs":[""],"patches":{"php5":["vendor: http://patch-tracking.debian.net/patch/series/view/php5/5.2.6.dfsg.1-2/BG-initializing-fix.patch","upstream: http://cvs.php.net/viewvc.cgi/php-src/ext/standard/basic_functions.c?r1=1.725.2.31.2.78&r2=1.725.2.31.2.79&diff_format=u","upstream: http://cvs.php.net/viewvc.cgi/php-src/sapi/apache/mod_php5.c?r1=1.19.2.7.2.15&r2=1.19.2.7.2.16&diff_format=u"],"php4":[]},"tags":{},"packages":[{"name":"php4","source":"https://ubuntu.com/security/cve?package=php4","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=php4","debian":"https://tracker.debian.org/pkg/php4","statuses":[{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"php5","source":"https://ubuntu.com/security/cve?package=php5","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=php5","debian":"https://tracker.debian.org/pkg/php5","statuses":[{"release_codename":"dapper","status":"released","description":"5.1.2-1ubuntu3.13","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"5.2.3-1ubuntu6.5","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"5.2.4-2ubuntu5.5","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"5.2.6-2ubuntu4.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"5.2.6.dfsg.1-3ubuntu2","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"5.2.6.dfsg.1-3ubuntu2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.2.6.dfsg.1-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-720-1"],"notices":[{"id":"USN-720-1","title":"PHP vulnerabilities","summary":"PHP vulnerabilities","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.\n","references":[],"published":"2009-02-12T19:13:44.913639","description":"It was discovered that PHP did not properly enforce php_admin_value and\nphp_admin_flag restrictions in the Apache configuration file. A local attacker\ncould create a specially crafted PHP script that would bypass intended security\nrestrictions. This issue only applied to Ubuntu 6.06 LTS, 7.10, and 8.04 LTS.\n(CVE-2007-5900)\n\nIt was discovered that PHP did not correctly handle certain malformed font\nfiles. If a PHP application were tricked into processing a specially crafted\nfont file, an attacker may be able to cause a denial of service and possibly\nexecute arbitrary code with application privileges. (CVE-2008-3658)\n\nIt was discovered that PHP did not properly check the delimiter argument to the\nexplode function. If a script passed untrusted input to the explode function, an\nattacker could cause a denial of service and possibly execute arbitrary code\nwith application privileges.  (CVE-2008-3659) \n\nIt was discovered that PHP, when used as FastCGI module, did not properly\nsanitize requests. By performing a request with multiple dots preceding the\nextension, an attacker could cause a denial of service. (CVE-2008-3660)\n\nIt was discovered that PHP did not properly handle Unicode conversion in the\nmbstring extension. If a PHP application were tricked into processing a\nspecially crafted string containing an HTML entity, an attacker could execute\narbitrary code with application privileges. (CVE-2008-5557)\n\nIt was discovered that PHP did not properly initialize the page_uid and page_gid\nglobal variables for use by the SAPI php_getuid function. An attacker could\nexploit this issue to bypass safe_mode restrictions. (CVE-2008-5624)\n\nIt was dicovered that PHP did not properly enforce error_log safe_mode\nrestrictions when set by php_admin_flag in the Apache configuration file. A\nlocal attacker could create a specially crafted PHP script that would overwrite\narbitrary files. (CVE-2008-5625)\n\nIt was discovered that PHP contained a flaw in the ZipArchive::extractTo\nfunction. If a PHP application were tricked into processing a specially crafted\nzip file that had filenames containing \"..\", an attacker could write arbitrary\nfiles within the filesystem. This issue only applied to Ubuntu 7.10, 8.04 LTS,\nand 8.10. (CVE-2008-5658)\n\nUSN-557-1 fixed a vulnerability in the GD library. When using the GD library,\nPHP did not properly handle the return codes that were added in the security\nupdate. An attacker could exploit this issue with a specially crafted image file\nand cause PHP to crash, leading to a denial of service. This issue only applied\nto Ubuntu 6.06 LTS, and 7.10. (CVE-2007-3996)\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"php5","version":"5.2.3-1ubuntu6.5","description":"","is_source":true},{"name":"php5-cli","version":"5.2.3-1ubuntu6.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.3-1ubuntu6.5"},{"name":"php5-cgi","version":"5.2.3-1ubuntu6.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.3-1ubuntu6.5"},{"name":"php5-gd","version":"5.2.3-1ubuntu6.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.3-1ubuntu6.5"},{"name":"libapache2-mod-php5","version":"5.2.3-1ubuntu6.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.3-1ubuntu6.5"}],"dapper":[{"name":"php5","version":"5.1.2-1ubuntu3.13","description":"","is_source":true},{"name":"php5-cli","version":"5.1.2-1ubuntu3.13","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.13"},{"name":"php5-cgi","version":"5.1.2-1ubuntu3.13","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.13"},{"name":"php5-gd","version":"5.1.2-1ubuntu3.13","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.13"},{"name":"libapache2-mod-php5","version":"5.1.2-1ubuntu3.13","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.1.2-1ubuntu3.13"}],"intrepid":[{"name":"php5","version":"5.2.6-2ubuntu4.1","description":"","is_source":true},{"name":"php5-cli","version":"5.2.6-2ubuntu4.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.6-2ubuntu4.1"},{"name":"php5-cgi","version":"5.2.6-2ubuntu4.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.6-2ubuntu4.1"},{"name":"php5-gd","version":"5.2.6-2ubuntu4.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.6-2ubuntu4.1"},{"name":"libapache2-mod-php5","version":"5.2.6-2ubuntu4.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.6-2ubuntu4.1"},{"name":"libapache2-mod-php5filter","version":"5.2.6-2ubuntu4.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.6-2ubuntu4.1"}],"hardy":[{"name":"php5","version":"5.2.4-2ubuntu5.5","description":"","is_source":true},{"name":"php5-cli","version":"5.2.4-2ubuntu5.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.5"},{"name":"php5-cgi","version":"5.2.4-2ubuntu5.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.5"},{"name":"php5-gd","version":"5.2.4-2ubuntu5.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.5"},{"name":"libapache2-mod-php5","version":"5.2.4-2ubuntu5.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.2.4-2ubuntu5.5"}]},"type":"USN","cves_ids":["CVE-2008-3659","CVE-2007-5900","CVE-2007-3996","CVE-2008-5625","CVE-2008-5624","CVE-2008-5557","CVE-2008-3658","CVE-2008-3660","CVE-2008-5658"]}]},{"id":"CVE-2008-5513","published":"2008-12-17T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in the session-restore feature in Mozilla Firefox\n3.x before 3.0.5 and 2.x before 2.0.0.19 allows remote attackers to bypass\nthe same origin policy, inject content into documents associated with other\ndomains, and conduct cross-site scripting (XSS) attacks via unknown vectors\nrelated to restoration of SessionStore data.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-690-2","https://ubuntu.com/security/notices/USN-690-1","https://www.cve.org/CVERecord?id=CVE-2008-5513"],"bugs":[""],"patches":{"firefox":[],"firefox-3.0":[],"xulrunner":[],"xulrunner-1.9":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"dapper","status":"released","description":"1.5.dfsg+1.5.0.15~prepatch080614i-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"2.0.0.19+nobinonly1-0ubuntu0.7.10.1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.0.0.19+nobinonly1-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"3.0.5+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"3.0.5+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"3.0.5+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.0.0.19","component":null,"pocket":"security"}]},{"name":"firefox-3.0","source":"https://ubuntu.com/security/cve?package=firefox-3.0","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=firefox-3.0","debian":"https://tracker.debian.org/pkg/firefox-3.0","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"3.0.5+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"3.0.5+nobinonly-0ubuntu0.8.10.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"3.0.5+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.0.5","component":null,"pocket":"security"}]},{"name":"xulrunner","source":"https://ubuntu.com/security/cve?package=xulrunner","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=xulrunner","debian":"https://tracker.debian.org/pkg/xulrunner","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"1.8.1.18+nobinonly.b308.cvs20090331t155113-0ubuntu0.7.10.1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.8.1.18+nobinonly.b308.cvs20090331t155113-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.8.1.18+nobinonly.b308.cvs20090331t155113-0ubuntu0.8.10.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"xulrunner-1.9","source":"https://ubuntu.com/security/cve?package=xulrunner-1.9","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=xulrunner-1.9","debian":"https://tracker.debian.org/pkg/xulrunner-1.9","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.9.0.5+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.9.0.5+nobinonly-0ubuntu0.8.10.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.9.0.5+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-690-1","USN-690-2"],"notices":[{"id":"USN-690-1","title":"Firefox and xulrunner vulnerabilities","summary":"Firefox and xulrunner vulnerabilities","instructions":"After a standard system upgrade you need to restart Firefox and any\napplications that use xulrunner, such as Epiphany, to effect the necessary\nchanges.\n","references":[],"published":"2008-12-17T23:50:57.166327","description":"Several flaws were discovered in the browser engine. These problems could allow\nan attacker to crash the browser and possibly execute arbitrary code with user\nprivileges. (CVE-2008-5500, CVE-2008-5501, CVE-2008-5502)\n\nIt was discovered that Firefox did not properly handle persistent cookie data.\nIf a user were tricked into opening a malicious website, an attacker could\nwrite persistent data in the user's browser and track the user across browsing\nsessions. (CVE-2008-5505)\n\nMarius Schilder discovered that Firefox did not properly handle redirects to\nan outside domain when an XMLHttpRequest was made to a same-origin resource.\nIt's possible that sensitive information could be revealed in the\nXMLHttpRequest response. (CVE-2008-5506)\n\nChris Evans discovered that Firefox did not properly protect a user's data when\naccessing a same-domain Javascript URL that is redirected to an unparsable\nJavascript off-site resource. If a user were tricked into opening a malicious\nwebsite, an attacker may be able to steal a limited amount of private data.\n(CVE-2008-5507)\n\nChip Salzenberg, Justin Schuh, Tom Cross, and Peter William discovered Firefox\ndid not properly parse URLs when processing certain control characters.\n(CVE-2008-5508)\n\nKojima Hajime discovered that Firefox did not properly handle an escaped null\ncharacter. An attacker may be able to exploit this flaw to bypass script\nsanitization. (CVE-2008-5510)\n\nSeveral flaws were discovered in the Javascript engine. If a user were tricked\ninto opening a malicious website, an attacker could exploit this to execute\narbitrary Javascript code within the context of another website or with chrome\nprivileges. (CVE-2008-5511, CVE-2008-5512)\n\nFlaws were discovered in the session-restore feature of Firefox. If a user were\ntricked into opening a malicious website, an attacker could exploit this to\nperform cross-site scripting attacks or execute arbitrary Javascript code with\nchrome privileges. (CVE-2008-5513)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"firefox-3.0","version":"3.0.5+nobinonly-0ubuntu0.8.04.1","description":"","is_source":true},{"name":"xulrunner-1.9","version":"1.9.0.5+nobinonly-0ubuntu0.8.04.1","description":"","is_source":true},{"name":"firefox-3.0","version":"3.0.5+nobinonly-0ubuntu0.8.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.0.5+nobinonly-0ubuntu0.8.04.1"},{"name":"xulrunner-1.9","version":"1.9.0.5+nobinonly-0ubuntu0.8.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9/1.9.0.5+nobinonly-0ubuntu0.8.04.1"}],"intrepid":[{"name":"firefox-3.0","version":"3.0.5+nobinonly-0ubuntu0.8.10.1","description":"","is_source":true},{"name":"xulrunner-1.9","version":"1.9.0.5+nobinonly-0ubuntu0.8.10.1","description":"","is_source":true},{"name":"firefox-3.0","version":"3.0.5+nobinonly-0ubuntu0.8.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.0.5+nobinonly-0ubuntu0.8.10.1"},{"name":"abrowser","version":"3.0.5+nobinonly-0ubuntu0.8.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.0.5+nobinonly-0ubuntu0.8.10.1"},{"name":"xulrunner-1.9","version":"1.9.0.5+nobinonly-0ubuntu0.8.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9/1.9.0.5+nobinonly-0ubuntu0.8.10.1"}]},"type":"USN","cves_ids":["CVE-2008-5502","CVE-2008-5501","CVE-2008-5505","CVE-2008-5500","CVE-2008-5506","CVE-2008-5507","CVE-2008-5508","CVE-2008-5510","CVE-2008-5511","CVE-2008-5512","CVE-2008-5513"]},{"id":"USN-690-2","title":"Firefox vulnerabilities","summary":"Firefox vulnerabilities","instructions":"After a standard system upgrade you need to restart Firefox to effect the\nnecessary changes.\n","references":[],"published":"2008-12-18T00:08:10.708002","description":"Several flaws were discovered in the browser engine. These problems could allow\nan attacker to crash the browser and possibly execute arbitrary code with user\nprivileges. (CVE-2008-5500)\n\nBoris Zbarsky discovered that the same-origin check in Firefox could be\nbypassed by utilizing XBL-bindings. An attacker could exploit this to read data\nfrom other domains. (CVE-2008-5503)\n\nSeveral problems were discovered in the JavaScript engine. An attacker could\nexploit feed preview vulnerabilities to execute scripts from page content with\nchrome privileges. (CVE-2008-5504)\n\nMarius Schilder discovered that Firefox did not properly handle redirects to\nan outside domain when an XMLHttpRequest was made to a same-origin resource.\nIt's possible that sensitive information could be revealed in the\nXMLHttpRequest response. (CVE-2008-5506)\n\nChris Evans discovered that Firefox did not properly protect a user's data when\naccessing a same-domain Javascript URL that is redirected to an unparsable\nJavascript off-site resource. If a user were tricked into opening a malicious\nwebsite, an attacker may be able to steal a limited amount of private data.\n(CVE-2008-5507)\n\nChip Salzenberg, Justin Schuh, Tom Cross, and Peter William discovered Firefox\ndid not properly parse URLs when processing certain control characters.\n(CVE-2008-5508)\n\nKojima Hajime discovered that Firefox did not properly handle an escaped null\ncharacter. An attacker may be able to exploit this flaw to bypass script\nsanitization. (CVE-2008-5510)\n\nSeveral flaws were discovered in the Javascript engine. If a user were tricked\ninto opening a malicious website, an attacker could exploit this to execute\narbitrary Javascript code within the context of another website or with chrome\nprivileges. (CVE-2008-5511, CVE-2008-5512)\n\nFlaws were discovered in the session-restore feature of Firefox. If a user were\ntricked into opening a malicious website, an attacker could exploit this to\nperform cross-site scripting attacks or execute arbitrary Javascript code with\nchrome privileges. (CVE-2008-5513)\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"firefox","version":"2.0.0.19+nobinonly1-0ubuntu0.7.10.1","description":"","is_source":true},{"name":"firefox","version":"2.0.0.19+nobinonly1-0ubuntu0.7.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/2.0.0.19+nobinonly1-0ubuntu0.7.10.1"}]},"type":"USN","cves_ids":["CVE-2008-5510","CVE-2008-5504","CVE-2008-5508","CVE-2008-5513","CVE-2008-5500","CVE-2008-5503","CVE-2008-5506","CVE-2008-5507","CVE-2008-5511","CVE-2008-5512"]}]},{"id":"CVE-2008-5512","published":"2008-12-17T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple unspecified vulnerabilities in Mozilla Firefox 3.x before 3.0.5\nand 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x\nbefore 1.1.14 allow remote attackers to run arbitrary JavaScript with\nchrome privileges via unknown vectors in which \"page content can pollute\nXPCNativeWrappers.\"","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-690-3","https://ubuntu.com/security/notices/USN-690-2","https://ubuntu.com/security/notices/USN-690-1","https://ubuntu.com/security/notices/USN-701-1","https://ubuntu.com/security/notices/USN-701-2","https://www.cve.org/CVERecord?id=CVE-2008-5512"],"bugs":[""],"patches":{"firefox":[],"firefox-3.0":[],"xulrunner":[],"xulrunner-1.9":[],"seamonkey":[],"iceape":[],"thunderbird":[],"mozilla-thunderbird":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"dapper","status":"released","description":"1.5.dfsg+1.5.0.15~prepatch080614i-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"2.0.0.19+nobinonly1-0ubuntu0.7.10.1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.0.0.19+nobinonly1-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"3.0.5+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"3.0.5+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"3.0.5+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.0.0.19","component":null,"pocket":"security"}]},{"name":"firefox-3.0","source":"https://ubuntu.com/security/cve?package=firefox-3.0","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=firefox-3.0","debian":"https://tracker.debian.org/pkg/firefox-3.0","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"3.0.5+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"3.0.5+nobinonly-0ubuntu0.8.10.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"3.0.5+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.0.5","component":null,"pocket":"security"}]},{"name":"iceape","source":"https://ubuntu.com/security/cve?package=iceape","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=iceape","debian":"https://tracker.debian.org/pkg/iceape","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.1.14","component":null,"pocket":"security"}]},{"name":"mozilla-thunderbird","source":"https://ubuntu.com/security/cve?package=mozilla-thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mozilla-thunderbird","debian":"https://tracker.debian.org/pkg/mozilla-thunderbird","statuses":[{"release_codename":"dapper","status":"released","description":"1.5.0.13+1.5.0.15~prepatch080614i-0ubuntu0.6.06.1","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"seamonkey","source":"https://ubuntu.com/security/cve?package=seamonkey","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=seamonkey","debian":"https://tracker.debian.org/pkg/seamonkey","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.1.15+nobinonly-0ubuntu0.8.04.2","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.1.15+nobinonly-0ubuntu0.8.10.2","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.1.15+nobinonly-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1.1.15+nobinonly-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"1.1.15+nobinonly-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"1.1.15+nobinonly-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"1.1.15+nobinonly-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.1.14","component":null,"pocket":"security"}]},{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"2.0.0.19+nobinonly-0ubuntu0.7.10.1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.0.0.19+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"2.0.0.19+nobinonly-0ubuntu0.8.10.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.0.0.19+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.0.0.19+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.0.0.19+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"2.0.0.19+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"2.0.0.19+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.0.0.19","component":null,"pocket":"security"}]},{"name":"xulrunner","source":"https://ubuntu.com/security/cve?package=xulrunner","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=xulrunner","debian":"https://tracker.debian.org/pkg/xulrunner","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"1.8.1.18+nobinonly.b308.cvs20090331t155113-0ubuntu0.7.10.1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.8.1.18+nobinonly.b308.cvs20090331t155113-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.8.1.18+nobinonly.b308.cvs20090331t155113-0ubuntu0.8.10.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"xulrunner-1.9","source":"https://ubuntu.com/security/cve?package=xulrunner-1.9","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=xulrunner-1.9","debian":"https://tracker.debian.org/pkg/xulrunner-1.9","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.9.0.5+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.9.0.5+nobinonly-0ubuntu0.8.10.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.9.0.5+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-690-1","USN-690-3","USN-690-2","USN-701-1","USN-701-2"],"notices":[{"id":"USN-690-1","title":"Firefox and xulrunner vulnerabilities","summary":"Firefox and xulrunner vulnerabilities","instructions":"After a standard system upgrade you need to restart Firefox and any\napplications that use xulrunner, such as Epiphany, to effect the necessary\nchanges.\n","references":[],"published":"2008-12-17T23:50:57.166327","description":"Several flaws were discovered in the browser engine. These problems could allow\nan attacker to crash the browser and possibly execute arbitrary code with user\nprivileges. (CVE-2008-5500, CVE-2008-5501, CVE-2008-5502)\n\nIt was discovered that Firefox did not properly handle persistent cookie data.\nIf a user were tricked into opening a malicious website, an attacker could\nwrite persistent data in the user's browser and track the user across browsing\nsessions. (CVE-2008-5505)\n\nMarius Schilder discovered that Firefox did not properly handle redirects to\nan outside domain when an XMLHttpRequest was made to a same-origin resource.\nIt's possible that sensitive information could be revealed in the\nXMLHttpRequest response. (CVE-2008-5506)\n\nChris Evans discovered that Firefox did not properly protect a user's data when\naccessing a same-domain Javascript URL that is redirected to an unparsable\nJavascript off-site resource. If a user were tricked into opening a malicious\nwebsite, an attacker may be able to steal a limited amount of private data.\n(CVE-2008-5507)\n\nChip Salzenberg, Justin Schuh, Tom Cross, and Peter William discovered Firefox\ndid not properly parse URLs when processing certain control characters.\n(CVE-2008-5508)\n\nKojima Hajime discovered that Firefox did not properly handle an escaped null\ncharacter. An attacker may be able to exploit this flaw to bypass script\nsanitization. (CVE-2008-5510)\n\nSeveral flaws were discovered in the Javascript engine. If a user were tricked\ninto opening a malicious website, an attacker could exploit this to execute\narbitrary Javascript code within the context of another website or with chrome\nprivileges. (CVE-2008-5511, CVE-2008-5512)\n\nFlaws were discovered in the session-restore feature of Firefox. If a user were\ntricked into opening a malicious website, an attacker could exploit this to\nperform cross-site scripting attacks or execute arbitrary Javascript code with\nchrome privileges. (CVE-2008-5513)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"firefox-3.0","version":"3.0.5+nobinonly-0ubuntu0.8.04.1","description":"","is_source":true},{"name":"xulrunner-1.9","version":"1.9.0.5+nobinonly-0ubuntu0.8.04.1","description":"","is_source":true},{"name":"firefox-3.0","version":"3.0.5+nobinonly-0ubuntu0.8.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.0.5+nobinonly-0ubuntu0.8.04.1"},{"name":"xulrunner-1.9","version":"1.9.0.5+nobinonly-0ubuntu0.8.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9/1.9.0.5+nobinonly-0ubuntu0.8.04.1"}],"intrepid":[{"name":"firefox-3.0","version":"3.0.5+nobinonly-0ubuntu0.8.10.1","description":"","is_source":true},{"name":"xulrunner-1.9","version":"1.9.0.5+nobinonly-0ubuntu0.8.10.1","description":"","is_source":true},{"name":"firefox-3.0","version":"3.0.5+nobinonly-0ubuntu0.8.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.0.5+nobinonly-0ubuntu0.8.10.1"},{"name":"abrowser","version":"3.0.5+nobinonly-0ubuntu0.8.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.0.5+nobinonly-0ubuntu0.8.10.1"},{"name":"xulrunner-1.9","version":"1.9.0.5+nobinonly-0ubuntu0.8.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9/1.9.0.5+nobinonly-0ubuntu0.8.10.1"}]},"type":"USN","cves_ids":["CVE-2008-5502","CVE-2008-5501","CVE-2008-5505","CVE-2008-5500","CVE-2008-5506","CVE-2008-5507","CVE-2008-5508","CVE-2008-5510","CVE-2008-5511","CVE-2008-5512","CVE-2008-5513"]},{"id":"USN-690-3","title":"Firefox vulnerabilities","summary":"Firefox vulnerabilities","instructions":"After a standard system upgrade you need to restart Firefox to effect the\nnecessary changes.\n","references":[],"published":"2008-12-18T00:17:53.636632","description":"Several flaws were discovered in the browser engine. These problems could allow\nan attacker to crash the browser and possibly execute arbitrary code with user\nprivileges. (CVE-2008-5500)\n\nBoris Zbarsky discovered that the same-origin check in Firefox could be\nbypassed by utilizing XBL-bindings. An attacker could exploit this to read data\nfrom other domains. (CVE-2008-5503)\n\nMarius Schilder discovered that Firefox did not properly handle redirects to\nan outside domain when an XMLHttpRequest was made to a same-origin resource.\nIt's possible that sensitive information could be revealed in the\nXMLHttpRequest response. (CVE-2008-5506)\n\nChris Evans discovered that Firefox did not properly protect a user's data when\naccessing a same-domain Javascript URL that is redirected to an unparsable\nJavascript off-site resource. If a user were tricked into opening a malicious\nwebsite, an attacker may be able to steal a limited amount of private data.\n(CVE-2008-5507)\n\nSeveral flaws were discovered in the Javascript engine. If a user were tricked\ninto opening a malicious website, an attacker could exploit this to execute\narbitrary Javascript code within the context of another website or with chrome\nprivileges. (CVE-2008-5511, CVE-2008-5512)\n","is_hidden":false,"release_packages":{"dapper":[{"name":"firefox","version":"1.5.dfsg+1.5.0.15~prepatch080614i-0ubuntu1","description":"","is_source":true},{"name":"firefox","version":"1.5.dfsg+1.5.0.15~prepatch080614i-0ubuntu1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/1.5.dfsg+1.5.0.15~prepatch080614i-0ubuntu1"}]},"type":"USN","cves_ids":["CVE-2008-5503","CVE-2008-5507","CVE-2008-5512","CVE-2008-5511","CVE-2008-5500","CVE-2008-5506"]},{"id":"USN-690-2","title":"Firefox vulnerabilities","summary":"Firefox vulnerabilities","instructions":"After a standard system upgrade you need to restart Firefox to effect the\nnecessary changes.\n","references":[],"published":"2008-12-18T00:08:10.708002","description":"Several flaws were discovered in the browser engine. These problems could allow\nan attacker to crash the browser and possibly execute arbitrary code with user\nprivileges. (CVE-2008-5500)\n\nBoris Zbarsky discovered that the same-origin check in Firefox could be\nbypassed by utilizing XBL-bindings. An attacker could exploit this to read data\nfrom other domains. (CVE-2008-5503)\n\nSeveral problems were discovered in the JavaScript engine. An attacker could\nexploit feed preview vulnerabilities to execute scripts from page content with\nchrome privileges. (CVE-2008-5504)\n\nMarius Schilder discovered that Firefox did not properly handle redirects to\nan outside domain when an XMLHttpRequest was made to a same-origin resource.\nIt's possible that sensitive information could be revealed in the\nXMLHttpRequest response. (CVE-2008-5506)\n\nChris Evans discovered that Firefox did not properly protect a user's data when\naccessing a same-domain Javascript URL that is redirected to an unparsable\nJavascript off-site resource. If a user were tricked into opening a malicious\nwebsite, an attacker may be able to steal a limited amount of private data.\n(CVE-2008-5507)\n\nChip Salzenberg, Justin Schuh, Tom Cross, and Peter William discovered Firefox\ndid not properly parse URLs when processing certain control characters.\n(CVE-2008-5508)\n\nKojima Hajime discovered that Firefox did not properly handle an escaped null\ncharacter. An attacker may be able to exploit this flaw to bypass script\nsanitization. (CVE-2008-5510)\n\nSeveral flaws were discovered in the Javascript engine. If a user were tricked\ninto opening a malicious website, an attacker could exploit this to execute\narbitrary Javascript code within the context of another website or with chrome\nprivileges. (CVE-2008-5511, CVE-2008-5512)\n\nFlaws were discovered in the session-restore feature of Firefox. If a user were\ntricked into opening a malicious website, an attacker could exploit this to\nperform cross-site scripting attacks or execute arbitrary Javascript code with\nchrome privileges. (CVE-2008-5513)\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"firefox","version":"2.0.0.19+nobinonly1-0ubuntu0.7.10.1","description":"","is_source":true},{"name":"firefox","version":"2.0.0.19+nobinonly1-0ubuntu0.7.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/2.0.0.19+nobinonly1-0ubuntu0.7.10.1"}]},"type":"USN","cves_ids":["CVE-2008-5510","CVE-2008-5504","CVE-2008-5508","CVE-2008-5513","CVE-2008-5500","CVE-2008-5503","CVE-2008-5506","CVE-2008-5507","CVE-2008-5511","CVE-2008-5512"]},{"id":"USN-701-1","title":"Thunderbird vulnerabilities","summary":"Thunderbird vulnerabilities","instructions":"After a standard system upgrade you need to restart Thunderbird to effect\nthe necessary changes.\n","references":[],"published":"2009-01-06T23:17:08.901828","description":"Several flaws were discovered in the browser engine. If a user had Javascript\nenabled, these problems could allow an attacker to crash Thunderbird and\npossibly execute arbitrary code with user privileges. (CVE-2008-5500)\n\nBoris Zbarsky discovered that the same-origin check in Thunderbird could be\nbypassed by utilizing XBL-bindings. If a user had Javascript enabled, an\nattacker could exploit this to read data from other domains. (CVE-2008-5503)\n\nMarius Schilder discovered that Thunderbird did not properly handle redirects\nto an outside domain when an XMLHttpRequest was made to a same-origin resource.\nWhen Javascript is enabled, it's possible that sensitive information could be\nrevealed in the XMLHttpRequest response. (CVE-2008-5506)\n\nChris Evans discovered that Thunderbird did not properly protect a user's data\nwhen accessing a same-domain Javascript URL that is redirected to an unparsable\nJavascript off-site resource. If a user were tricked into opening a malicious\nwebsite and had Javascript enabled, an attacker may be able to steal a limited\namount of private data. (CVE-2008-5507)\n\nChip Salzenberg, Justin Schuh, Tom Cross, and Peter William discovered\nThunderbird did not properly parse URLs when processing certain control\ncharacters. (CVE-2008-5508)\n\nKojima Hajime discovered that Thunderbird did not properly handle an escaped\nnull character. An attacker may be able to exploit this flaw to bypass script\nsanitization. (CVE-2008-5510)\n\nSeveral flaws were discovered in the Javascript engine. If a user were tricked\ninto opening a malicious website and had Javascript enabled, an attacker could\nexploit this to execute arbitrary Javascript code within the context of another\nwebsite or with chrome privileges. (CVE-2008-5511, CVE-2008-5512)\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"thunderbird","version":"2.0.0.19+nobinonly-0ubuntu0.7.10.1","description":"","is_source":true},{"name":"thunderbird","version":"2.0.0.19+nobinonly-0ubuntu0.7.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/2.0.0.19+nobinonly-0ubuntu0.7.10.1"}],"intrepid":[{"name":"thunderbird","version":"2.0.0.19+nobinonly-0ubuntu0.8.10.1","description":"","is_source":true},{"name":"thunderbird","version":"2.0.0.19+nobinonly-0ubuntu0.8.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/2.0.0.19+nobinonly-0ubuntu0.8.10.1"}],"hardy":[{"name":"thunderbird","version":"2.0.0.19+nobinonly-0ubuntu0.8.04.1","description":"","is_source":true},{"name":"thunderbird","version":"2.0.0.19+nobinonly-0ubuntu0.8.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/2.0.0.19+nobinonly-0ubuntu0.8.04.1"}]},"type":"USN","cves_ids":["CVE-2008-5500","CVE-2008-5503","CVE-2008-5506","CVE-2008-5507","CVE-2008-5508","CVE-2008-5510","CVE-2008-5511","CVE-2008-5512"]},{"id":"USN-701-2","title":"Thunderbird vulnerabilities","summary":"Thunderbird vulnerabilities","instructions":"After a standard system upgrade you need to restart Thunderbird to effect\nthe necessary changes.\n","references":[],"published":"2009-01-06T23:31:22.903118","description":"Several flaws were discovered in the browser engine. If a user had Javascript\nenabled, these problems could allow an attacker to crash Thunderbird and\npossibly execute arbitrary code with user privileges. (CVE-2008-5500)\n\nBoris Zbarsky discovered that the same-origin check in Thunderbird could be\nbypassed by utilizing XBL-bindings. If a user had Javascript enabled, an\nattacker could exploit this to read data from other domains. (CVE-2008-5503)\n\nMarius Schilder discovered that Thunderbird did not properly handle redirects\nto an outside domain when an XMLHttpRequest was made to a same-origin resource.\nWhen Javascript is enabled, it's possible that sensitive information could be\nrevealed in the XMLHttpRequest response. (CVE-2008-5506)\n\nChris Evans discovered that Thunderbird did not properly protect a user's data\nwhen accessing a same-domain Javascript URL that is redirected to an unparsable\nJavascript off-site resource. If a user were tricked into opening a malicious\nwebsite and had Javascript enabled, an attacker may be able to steal a limited\namount of private data. (CVE-2008-5507)\n\nChip Salzenberg, Justin Schuh, Tom Cross, and Peter William discovered\nThunderbird did not properly parse URLs when processing certain control\ncharacters. (CVE-2008-5508)\n\nSeveral flaws were discovered in the Javascript engine. If a user were tricked\ninto opening a malicious website and had Javascript enabled, an attacker could\nexploit this to execute arbitrary Javascript code within the context of another\nwebsite or with chrome privileges. (CVE-2008-5511, CVE-2008-5512)\n","is_hidden":false,"release_packages":{"dapper":[{"name":"mozilla-thunderbird","version":"1.5.0.13+1.5.0.15~prepatch080614i-0ubuntu0.6.06.1","description":"","is_source":true},{"name":"mozilla-thunderbird","version":"1.5.0.13+1.5.0.15~prepatch080614i-0ubuntu0.6.06.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/mozilla-thunderbird","version_link":"https://launchpad.net/ubuntu/+source/mozilla-thunderbird/1.5.0.13+1.5.0.15~prepatch080614i-0ubuntu0.6.06.1"}]},"type":"USN","cves_ids":["CVE-2008-5500","CVE-2008-5503","CVE-2008-5506","CVE-2008-5507","CVE-2008-5508","CVE-2008-5511","CVE-2008-5512"]}]},{"id":"CVE-2008-5511","published":"2008-12-17T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x\nbefore 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to\nbypass the same origin policy and conduct cross-site scripting (XSS)\nattacks via an XBL binding to an \"unloaded document.\"","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-690-3","https://ubuntu.com/security/notices/USN-690-2","https://ubuntu.com/security/notices/USN-690-1","https://ubuntu.com/security/notices/USN-701-1","https://ubuntu.com/security/notices/USN-701-2","https://www.cve.org/CVERecord?id=CVE-2008-5511"],"bugs":[""],"patches":{"firefox":[],"firefox-3.0":[],"xulrunner":[],"xulrunner-1.9":[],"seamonkey":[],"iceape":[],"thunderbird":[],"mozilla-thunderbird":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"dapper","status":"released","description":"1.5.dfsg+1.5.0.15~prepatch080614i-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"2.0.0.19+nobinonly1-0ubuntu0.7.10.1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.0.0.19+nobinonly1-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"3.0.5+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"3.0.5+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"3.0.5+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.0.0.19","component":null,"pocket":"security"}]},{"name":"firefox-3.0","source":"https://ubuntu.com/security/cve?package=firefox-3.0","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=firefox-3.0","debian":"https://tracker.debian.org/pkg/firefox-3.0","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"3.0.5+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"3.0.5+nobinonly-0ubuntu0.8.10.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"3.0.5+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.0.5","component":null,"pocket":"security"}]},{"name":"iceape","source":"https://ubuntu.com/security/cve?package=iceape","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=iceape","debian":"https://tracker.debian.org/pkg/iceape","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.1.14","component":null,"pocket":"security"}]},{"name":"mozilla-thunderbird","source":"https://ubuntu.com/security/cve?package=mozilla-thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mozilla-thunderbird","debian":"https://tracker.debian.org/pkg/mozilla-thunderbird","statuses":[{"release_codename":"dapper","status":"released","description":"1.5.0.13+1.5.0.15~prepatch080614i-0ubuntu0.6.06.1","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"seamonkey","source":"https://ubuntu.com/security/cve?package=seamonkey","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=seamonkey","debian":"https://tracker.debian.org/pkg/seamonkey","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.1.15+nobinonly-0ubuntu0.8.04.2","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.1.15+nobinonly-0ubuntu0.8.10.2","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.1.15+nobinonly-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1.1.15+nobinonly-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"1.1.15+nobinonly-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"1.1.15+nobinonly-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"1.1.15+nobinonly-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.1.14","component":null,"pocket":"security"}]},{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"2.0.0.19+nobinonly-0ubuntu0.7.10.1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.0.0.19+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"2.0.0.19+nobinonly-0ubuntu0.8.10.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.0.0.19+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.0.0.19+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.0.0.19+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"2.0.0.19+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"2.0.0.19+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.0.0.19","component":null,"pocket":"security"}]},{"name":"xulrunner","source":"https://ubuntu.com/security/cve?package=xulrunner","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=xulrunner","debian":"https://tracker.debian.org/pkg/xulrunner","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"1.8.1.18+nobinonly.b308.cvs20090331t155113-0ubuntu0.7.10.1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.8.1.18+nobinonly.b308.cvs20090331t155113-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.8.1.18+nobinonly.b308.cvs20090331t155113-0ubuntu0.8.10.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"xulrunner-1.9","source":"https://ubuntu.com/security/cve?package=xulrunner-1.9","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=xulrunner-1.9","debian":"https://tracker.debian.org/pkg/xulrunner-1.9","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.9.0.5+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.9.0.5+nobinonly-0ubuntu0.8.10.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.9.0.5+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-690-1","USN-690-3","USN-690-2","USN-701-1","USN-701-2"],"notices":[{"id":"USN-690-1","title":"Firefox and xulrunner vulnerabilities","summary":"Firefox and xulrunner vulnerabilities","instructions":"After a standard system upgrade you need to restart Firefox and any\napplications that use xulrunner, such as Epiphany, to effect the necessary\nchanges.\n","references":[],"published":"2008-12-17T23:50:57.166327","description":"Several flaws were discovered in the browser engine. These problems could allow\nan attacker to crash the browser and possibly execute arbitrary code with user\nprivileges. (CVE-2008-5500, CVE-2008-5501, CVE-2008-5502)\n\nIt was discovered that Firefox did not properly handle persistent cookie data.\nIf a user were tricked into opening a malicious website, an attacker could\nwrite persistent data in the user's browser and track the user across browsing\nsessions. (CVE-2008-5505)\n\nMarius Schilder discovered that Firefox did not properly handle redirects to\nan outside domain when an XMLHttpRequest was made to a same-origin resource.\nIt's possible that sensitive information could be revealed in the\nXMLHttpRequest response. (CVE-2008-5506)\n\nChris Evans discovered that Firefox did not properly protect a user's data when\naccessing a same-domain Javascript URL that is redirected to an unparsable\nJavascript off-site resource. If a user were tricked into opening a malicious\nwebsite, an attacker may be able to steal a limited amount of private data.\n(CVE-2008-5507)\n\nChip Salzenberg, Justin Schuh, Tom Cross, and Peter William discovered Firefox\ndid not properly parse URLs when processing certain control characters.\n(CVE-2008-5508)\n\nKojima Hajime discovered that Firefox did not properly handle an escaped null\ncharacter. An attacker may be able to exploit this flaw to bypass script\nsanitization. (CVE-2008-5510)\n\nSeveral flaws were discovered in the Javascript engine. If a user were tricked\ninto opening a malicious website, an attacker could exploit this to execute\narbitrary Javascript code within the context of another website or with chrome\nprivileges. (CVE-2008-5511, CVE-2008-5512)\n\nFlaws were discovered in the session-restore feature of Firefox. If a user were\ntricked into opening a malicious website, an attacker could exploit this to\nperform cross-site scripting attacks or execute arbitrary Javascript code with\nchrome privileges. (CVE-2008-5513)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"firefox-3.0","version":"3.0.5+nobinonly-0ubuntu0.8.04.1","description":"","is_source":true},{"name":"xulrunner-1.9","version":"1.9.0.5+nobinonly-0ubuntu0.8.04.1","description":"","is_source":true},{"name":"firefox-3.0","version":"3.0.5+nobinonly-0ubuntu0.8.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.0.5+nobinonly-0ubuntu0.8.04.1"},{"name":"xulrunner-1.9","version":"1.9.0.5+nobinonly-0ubuntu0.8.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9/1.9.0.5+nobinonly-0ubuntu0.8.04.1"}],"intrepid":[{"name":"firefox-3.0","version":"3.0.5+nobinonly-0ubuntu0.8.10.1","description":"","is_source":true},{"name":"xulrunner-1.9","version":"1.9.0.5+nobinonly-0ubuntu0.8.10.1","description":"","is_source":true},{"name":"firefox-3.0","version":"3.0.5+nobinonly-0ubuntu0.8.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.0.5+nobinonly-0ubuntu0.8.10.1"},{"name":"abrowser","version":"3.0.5+nobinonly-0ubuntu0.8.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.0.5+nobinonly-0ubuntu0.8.10.1"},{"name":"xulrunner-1.9","version":"1.9.0.5+nobinonly-0ubuntu0.8.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9/1.9.0.5+nobinonly-0ubuntu0.8.10.1"}]},"type":"USN","cves_ids":["CVE-2008-5502","CVE-2008-5501","CVE-2008-5505","CVE-2008-5500","CVE-2008-5506","CVE-2008-5507","CVE-2008-5508","CVE-2008-5510","CVE-2008-5511","CVE-2008-5512","CVE-2008-5513"]},{"id":"USN-690-3","title":"Firefox vulnerabilities","summary":"Firefox vulnerabilities","instructions":"After a standard system upgrade you need to restart Firefox to effect the\nnecessary changes.\n","references":[],"published":"2008-12-18T00:17:53.636632","description":"Several flaws were discovered in the browser engine. These problems could allow\nan attacker to crash the browser and possibly execute arbitrary code with user\nprivileges. (CVE-2008-5500)\n\nBoris Zbarsky discovered that the same-origin check in Firefox could be\nbypassed by utilizing XBL-bindings. An attacker could exploit this to read data\nfrom other domains. (CVE-2008-5503)\n\nMarius Schilder discovered that Firefox did not properly handle redirects to\nan outside domain when an XMLHttpRequest was made to a same-origin resource.\nIt's possible that sensitive information could be revealed in the\nXMLHttpRequest response. (CVE-2008-5506)\n\nChris Evans discovered that Firefox did not properly protect a user's data when\naccessing a same-domain Javascript URL that is redirected to an unparsable\nJavascript off-site resource. If a user were tricked into opening a malicious\nwebsite, an attacker may be able to steal a limited amount of private data.\n(CVE-2008-5507)\n\nSeveral flaws were discovered in the Javascript engine. If a user were tricked\ninto opening a malicious website, an attacker could exploit this to execute\narbitrary Javascript code within the context of another website or with chrome\nprivileges. (CVE-2008-5511, CVE-2008-5512)\n","is_hidden":false,"release_packages":{"dapper":[{"name":"firefox","version":"1.5.dfsg+1.5.0.15~prepatch080614i-0ubuntu1","description":"","is_source":true},{"name":"firefox","version":"1.5.dfsg+1.5.0.15~prepatch080614i-0ubuntu1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/1.5.dfsg+1.5.0.15~prepatch080614i-0ubuntu1"}]},"type":"USN","cves_ids":["CVE-2008-5503","CVE-2008-5507","CVE-2008-5512","CVE-2008-5511","CVE-2008-5500","CVE-2008-5506"]},{"id":"USN-690-2","title":"Firefox vulnerabilities","summary":"Firefox vulnerabilities","instructions":"After a standard system upgrade you need to restart Firefox to effect the\nnecessary changes.\n","references":[],"published":"2008-12-18T00:08:10.708002","description":"Several flaws were discovered in the browser engine. These problems could allow\nan attacker to crash the browser and possibly execute arbitrary code with user\nprivileges. (CVE-2008-5500)\n\nBoris Zbarsky discovered that the same-origin check in Firefox could be\nbypassed by utilizing XBL-bindings. An attacker could exploit this to read data\nfrom other domains. (CVE-2008-5503)\n\nSeveral problems were discovered in the JavaScript engine. An attacker could\nexploit feed preview vulnerabilities to execute scripts from page content with\nchrome privileges. (CVE-2008-5504)\n\nMarius Schilder discovered that Firefox did not properly handle redirects to\nan outside domain when an XMLHttpRequest was made to a same-origin resource.\nIt's possible that sensitive information could be revealed in the\nXMLHttpRequest response. (CVE-2008-5506)\n\nChris Evans discovered that Firefox did not properly protect a user's data when\naccessing a same-domain Javascript URL that is redirected to an unparsable\nJavascript off-site resource. If a user were tricked into opening a malicious\nwebsite, an attacker may be able to steal a limited amount of private data.\n(CVE-2008-5507)\n\nChip Salzenberg, Justin Schuh, Tom Cross, and Peter William discovered Firefox\ndid not properly parse URLs when processing certain control characters.\n(CVE-2008-5508)\n\nKojima Hajime discovered that Firefox did not properly handle an escaped null\ncharacter. An attacker may be able to exploit this flaw to bypass script\nsanitization. (CVE-2008-5510)\n\nSeveral flaws were discovered in the Javascript engine. If a user were tricked\ninto opening a malicious website, an attacker could exploit this to execute\narbitrary Javascript code within the context of another website or with chrome\nprivileges. (CVE-2008-5511, CVE-2008-5512)\n\nFlaws were discovered in the session-restore feature of Firefox. If a user were\ntricked into opening a malicious website, an attacker could exploit this to\nperform cross-site scripting attacks or execute arbitrary Javascript code with\nchrome privileges. (CVE-2008-5513)\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"firefox","version":"2.0.0.19+nobinonly1-0ubuntu0.7.10.1","description":"","is_source":true},{"name":"firefox","version":"2.0.0.19+nobinonly1-0ubuntu0.7.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/2.0.0.19+nobinonly1-0ubuntu0.7.10.1"}]},"type":"USN","cves_ids":["CVE-2008-5510","CVE-2008-5504","CVE-2008-5508","CVE-2008-5513","CVE-2008-5500","CVE-2008-5503","CVE-2008-5506","CVE-2008-5507","CVE-2008-5511","CVE-2008-5512"]},{"id":"USN-701-1","title":"Thunderbird vulnerabilities","summary":"Thunderbird vulnerabilities","instructions":"After a standard system upgrade you need to restart Thunderbird to effect\nthe necessary changes.\n","references":[],"published":"2009-01-06T23:17:08.901828","description":"Several flaws were discovered in the browser engine. If a user had Javascript\nenabled, these problems could allow an attacker to crash Thunderbird and\npossibly execute arbitrary code with user privileges. (CVE-2008-5500)\n\nBoris Zbarsky discovered that the same-origin check in Thunderbird could be\nbypassed by utilizing XBL-bindings. If a user had Javascript enabled, an\nattacker could exploit this to read data from other domains. (CVE-2008-5503)\n\nMarius Schilder discovered that Thunderbird did not properly handle redirects\nto an outside domain when an XMLHttpRequest was made to a same-origin resource.\nWhen Javascript is enabled, it's possible that sensitive information could be\nrevealed in the XMLHttpRequest response. (CVE-2008-5506)\n\nChris Evans discovered that Thunderbird did not properly protect a user's data\nwhen accessing a same-domain Javascript URL that is redirected to an unparsable\nJavascript off-site resource. If a user were tricked into opening a malicious\nwebsite and had Javascript enabled, an attacker may be able to steal a limited\namount of private data. (CVE-2008-5507)\n\nChip Salzenberg, Justin Schuh, Tom Cross, and Peter William discovered\nThunderbird did not properly parse URLs when processing certain control\ncharacters. (CVE-2008-5508)\n\nKojima Hajime discovered that Thunderbird did not properly handle an escaped\nnull character. An attacker may be able to exploit this flaw to bypass script\nsanitization. (CVE-2008-5510)\n\nSeveral flaws were discovered in the Javascript engine. If a user were tricked\ninto opening a malicious website and had Javascript enabled, an attacker could\nexploit this to execute arbitrary Javascript code within the context of another\nwebsite or with chrome privileges. (CVE-2008-5511, CVE-2008-5512)\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"thunderbird","version":"2.0.0.19+nobinonly-0ubuntu0.7.10.1","description":"","is_source":true},{"name":"thunderbird","version":"2.0.0.19+nobinonly-0ubuntu0.7.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/2.0.0.19+nobinonly-0ubuntu0.7.10.1"}],"intrepid":[{"name":"thunderbird","version":"2.0.0.19+nobinonly-0ubuntu0.8.10.1","description":"","is_source":true},{"name":"thunderbird","version":"2.0.0.19+nobinonly-0ubuntu0.8.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/2.0.0.19+nobinonly-0ubuntu0.8.10.1"}],"hardy":[{"name":"thunderbird","version":"2.0.0.19+nobinonly-0ubuntu0.8.04.1","description":"","is_source":true},{"name":"thunderbird","version":"2.0.0.19+nobinonly-0ubuntu0.8.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/2.0.0.19+nobinonly-0ubuntu0.8.04.1"}]},"type":"USN","cves_ids":["CVE-2008-5500","CVE-2008-5503","CVE-2008-5506","CVE-2008-5507","CVE-2008-5508","CVE-2008-5510","CVE-2008-5511","CVE-2008-5512"]},{"id":"USN-701-2","title":"Thunderbird vulnerabilities","summary":"Thunderbird vulnerabilities","instructions":"After a standard system upgrade you need to restart Thunderbird to effect\nthe necessary changes.\n","references":[],"published":"2009-01-06T23:31:22.903118","description":"Several flaws were discovered in the browser engine. If a user had Javascript\nenabled, these problems could allow an attacker to crash Thunderbird and\npossibly execute arbitrary code with user privileges. (CVE-2008-5500)\n\nBoris Zbarsky discovered that the same-origin check in Thunderbird could be\nbypassed by utilizing XBL-bindings. If a user had Javascript enabled, an\nattacker could exploit this to read data from other domains. (CVE-2008-5503)\n\nMarius Schilder discovered that Thunderbird did not properly handle redirects\nto an outside domain when an XMLHttpRequest was made to a same-origin resource.\nWhen Javascript is enabled, it's possible that sensitive information could be\nrevealed in the XMLHttpRequest response. (CVE-2008-5506)\n\nChris Evans discovered that Thunderbird did not properly protect a user's data\nwhen accessing a same-domain Javascript URL that is redirected to an unparsable\nJavascript off-site resource. If a user were tricked into opening a malicious\nwebsite and had Javascript enabled, an attacker may be able to steal a limited\namount of private data. (CVE-2008-5507)\n\nChip Salzenberg, Justin Schuh, Tom Cross, and Peter William discovered\nThunderbird did not properly parse URLs when processing certain control\ncharacters. (CVE-2008-5508)\n\nSeveral flaws were discovered in the Javascript engine. If a user were tricked\ninto opening a malicious website and had Javascript enabled, an attacker could\nexploit this to execute arbitrary Javascript code within the context of another\nwebsite or with chrome privileges. (CVE-2008-5511, CVE-2008-5512)\n","is_hidden":false,"release_packages":{"dapper":[{"name":"mozilla-thunderbird","version":"1.5.0.13+1.5.0.15~prepatch080614i-0ubuntu0.6.06.1","description":"","is_source":true},{"name":"mozilla-thunderbird","version":"1.5.0.13+1.5.0.15~prepatch080614i-0ubuntu0.6.06.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/mozilla-thunderbird","version_link":"https://launchpad.net/ubuntu/+source/mozilla-thunderbird/1.5.0.13+1.5.0.15~prepatch080614i-0ubuntu0.6.06.1"}]},"type":"USN","cves_ids":["CVE-2008-5500","CVE-2008-5503","CVE-2008-5506","CVE-2008-5507","CVE-2008-5508","CVE-2008-5511","CVE-2008-5512"]}]},{"id":"CVE-2008-5510","published":"2008-12-17T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe CSS parser in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19,\nThunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 ignores\nthe '\\0' escaped null character, which might allow remote attackers to\nbypass protection mechanisms such as sanitization routines.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-690-2","https://ubuntu.com/security/notices/USN-690-1","https://ubuntu.com/security/notices/USN-701-1","https://ubuntu.com/security/notices/USN-717-3","https://www.cve.org/CVERecord?id=CVE-2008-5510"],"bugs":[""],"patches":{"firefox":[],"firefox-3.0":[],"xulrunner":[],"xulrunner-1.9":[],"seamonkey":[],"iceape":[],"thunderbird":[],"mozilla-thunderbird":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"dapper","status":"released","description":"1.5.dfsg+1.5.0.15~prepatch080614i-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"2.0.0.19+nobinonly1-0ubuntu0.7.10.1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.0.0.19+nobinonly1-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"3.0.5+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"3.0.5+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"3.0.5+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.0.0.19","component":null,"pocket":"security"}]},{"name":"firefox-3.0","source":"https://ubuntu.com/security/cve?package=firefox-3.0","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=firefox-3.0","debian":"https://tracker.debian.org/pkg/firefox-3.0","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"3.0.5+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"3.0.5+nobinonly-0ubuntu0.8.10.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"3.0.5+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.0.5","component":null,"pocket":"security"}]},{"name":"iceape","source":"https://ubuntu.com/security/cve?package=iceape","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=iceape","debian":"https://tracker.debian.org/pkg/iceape","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.1.14","component":null,"pocket":"security"}]},{"name":"mozilla-thunderbird","source":"https://ubuntu.com/security/cve?package=mozilla-thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mozilla-thunderbird","debian":"https://tracker.debian.org/pkg/mozilla-thunderbird","statuses":[{"release_codename":"dapper","status":"released","description":"1.5.0.13+1.5.0.15~prepatch080614i-0ubuntu0.6.06.1","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"seamonkey","source":"https://ubuntu.com/security/cve?package=seamonkey","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=seamonkey","debian":"https://tracker.debian.org/pkg/seamonkey","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.1.15+nobinonly-0ubuntu0.8.04.2","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.1.15+nobinonly-0ubuntu0.8.10.2","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.1.15+nobinonly-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1.1.15+nobinonly-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"1.1.15+nobinonly-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"1.1.15+nobinonly-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"1.1.15+nobinonly-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.1.14","component":null,"pocket":"security"}]},{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"2.0.0.19+nobinonly-0ubuntu0.7.10.1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.0.0.19+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"2.0.0.19+nobinonly-0ubuntu0.8.10.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.0.0.19+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.0.0.19+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.0.0.19+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"2.0.0.19+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"2.0.0.19+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.0.0.19","component":null,"pocket":"security"}]},{"name":"xulrunner","source":"https://ubuntu.com/security/cve?package=xulrunner","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=xulrunner","debian":"https://tracker.debian.org/pkg/xulrunner","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"1.8.1.18+nobinonly.b308.cvs20090331t155113-0ubuntu0.7.10.1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.8.1.18+nobinonly.b308.cvs20090331t155113-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.8.1.18+nobinonly.b308.cvs20090331t155113-0ubuntu0.8.10.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"xulrunner-1.9","source":"https://ubuntu.com/security/cve?package=xulrunner-1.9","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=xulrunner-1.9","debian":"https://tracker.debian.org/pkg/xulrunner-1.9","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.9.0.5+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.9.0.5+nobinonly-0ubuntu0.8.10.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.9.0.5+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-717-3","USN-690-1","USN-690-2","USN-701-1"],"notices":[{"id":"USN-717-3","title":"Firefox vulnerabilities","summary":"Firefox vulnerabilities","instructions":"After a standard system upgrade you need to restart Firefox to effect the\nnecessary changes.\n","references":[],"published":"2009-02-11T01:44:47.009308","description":"Kojima Hajime discovered that Firefox did not properly handle an escaped null\ncharacter. An attacker may be able to exploit this flaw to bypass script\nsanitization. (CVE-2008-5510)\n\nWladimir Palant discovered that Firefox did not restrict access to cookies in\nHTTP response headers. If a user were tricked into opening a malicious web\npage, a remote attacker could view sensitive information. (CVE-2009-0357)\n","is_hidden":false,"release_packages":{"dapper":[{"name":"firefox","version":"1.5.dfsg+1.5.0.15~prepatch080614j-0ubuntu1","description":"","is_source":true},{"name":"firefox","version":"1.5.dfsg+1.5.0.15~prepatch080614j-0ubuntu1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/1.5.dfsg+1.5.0.15~prepatch080614j-0ubuntu1"}]},"type":"USN","cves_ids":["CVE-2008-5510","CVE-2009-0357"]},{"id":"USN-690-1","title":"Firefox and xulrunner vulnerabilities","summary":"Firefox and xulrunner vulnerabilities","instructions":"After a standard system upgrade you need to restart Firefox and any\napplications that use xulrunner, such as Epiphany, to effect the necessary\nchanges.\n","references":[],"published":"2008-12-17T23:50:57.166327","description":"Several flaws were discovered in the browser engine. These problems could allow\nan attacker to crash the browser and possibly execute arbitrary code with user\nprivileges. (CVE-2008-5500, CVE-2008-5501, CVE-2008-5502)\n\nIt was discovered that Firefox did not properly handle persistent cookie data.\nIf a user were tricked into opening a malicious website, an attacker could\nwrite persistent data in the user's browser and track the user across browsing\nsessions. (CVE-2008-5505)\n\nMarius Schilder discovered that Firefox did not properly handle redirects to\nan outside domain when an XMLHttpRequest was made to a same-origin resource.\nIt's possible that sensitive information could be revealed in the\nXMLHttpRequest response. (CVE-2008-5506)\n\nChris Evans discovered that Firefox did not properly protect a user's data when\naccessing a same-domain Javascript URL that is redirected to an unparsable\nJavascript off-site resource. If a user were tricked into opening a malicious\nwebsite, an attacker may be able to steal a limited amount of private data.\n(CVE-2008-5507)\n\nChip Salzenberg, Justin Schuh, Tom Cross, and Peter William discovered Firefox\ndid not properly parse URLs when processing certain control characters.\n(CVE-2008-5508)\n\nKojima Hajime discovered that Firefox did not properly handle an escaped null\ncharacter. An attacker may be able to exploit this flaw to bypass script\nsanitization. (CVE-2008-5510)\n\nSeveral flaws were discovered in the Javascript engine. If a user were tricked\ninto opening a malicious website, an attacker could exploit this to execute\narbitrary Javascript code within the context of another website or with chrome\nprivileges. (CVE-2008-5511, CVE-2008-5512)\n\nFlaws were discovered in the session-restore feature of Firefox. If a user were\ntricked into opening a malicious website, an attacker could exploit this to\nperform cross-site scripting attacks or execute arbitrary Javascript code with\nchrome privileges. (CVE-2008-5513)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"firefox-3.0","version":"3.0.5+nobinonly-0ubuntu0.8.04.1","description":"","is_source":true},{"name":"xulrunner-1.9","version":"1.9.0.5+nobinonly-0ubuntu0.8.04.1","description":"","is_source":true},{"name":"firefox-3.0","version":"3.0.5+nobinonly-0ubuntu0.8.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.0.5+nobinonly-0ubuntu0.8.04.1"},{"name":"xulrunner-1.9","version":"1.9.0.5+nobinonly-0ubuntu0.8.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9/1.9.0.5+nobinonly-0ubuntu0.8.04.1"}],"intrepid":[{"name":"firefox-3.0","version":"3.0.5+nobinonly-0ubuntu0.8.10.1","description":"","is_source":true},{"name":"xulrunner-1.9","version":"1.9.0.5+nobinonly-0ubuntu0.8.10.1","description":"","is_source":true},{"name":"firefox-3.0","version":"3.0.5+nobinonly-0ubuntu0.8.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.0.5+nobinonly-0ubuntu0.8.10.1"},{"name":"abrowser","version":"3.0.5+nobinonly-0ubuntu0.8.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.0.5+nobinonly-0ubuntu0.8.10.1"},{"name":"xulrunner-1.9","version":"1.9.0.5+nobinonly-0ubuntu0.8.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9/1.9.0.5+nobinonly-0ubuntu0.8.10.1"}]},"type":"USN","cves_ids":["CVE-2008-5502","CVE-2008-5501","CVE-2008-5505","CVE-2008-5500","CVE-2008-5506","CVE-2008-5507","CVE-2008-5508","CVE-2008-5510","CVE-2008-5511","CVE-2008-5512","CVE-2008-5513"]},{"id":"USN-690-2","title":"Firefox vulnerabilities","summary":"Firefox vulnerabilities","instructions":"After a standard system upgrade you need to restart Firefox to effect the\nnecessary changes.\n","references":[],"published":"2008-12-18T00:08:10.708002","description":"Several flaws were discovered in the browser engine. These problems could allow\nan attacker to crash the browser and possibly execute arbitrary code with user\nprivileges. (CVE-2008-5500)\n\nBoris Zbarsky discovered that the same-origin check in Firefox could be\nbypassed by utilizing XBL-bindings. An attacker could exploit this to read data\nfrom other domains. (CVE-2008-5503)\n\nSeveral problems were discovered in the JavaScript engine. An attacker could\nexploit feed preview vulnerabilities to execute scripts from page content with\nchrome privileges. (CVE-2008-5504)\n\nMarius Schilder discovered that Firefox did not properly handle redirects to\nan outside domain when an XMLHttpRequest was made to a same-origin resource.\nIt's possible that sensitive information could be revealed in the\nXMLHttpRequest response. (CVE-2008-5506)\n\nChris Evans discovered that Firefox did not properly protect a user's data when\naccessing a same-domain Javascript URL that is redirected to an unparsable\nJavascript off-site resource. If a user were tricked into opening a malicious\nwebsite, an attacker may be able to steal a limited amount of private data.\n(CVE-2008-5507)\n\nChip Salzenberg, Justin Schuh, Tom Cross, and Peter William discovered Firefox\ndid not properly parse URLs when processing certain control characters.\n(CVE-2008-5508)\n\nKojima Hajime discovered that Firefox did not properly handle an escaped null\ncharacter. An attacker may be able to exploit this flaw to bypass script\nsanitization. (CVE-2008-5510)\n\nSeveral flaws were discovered in the Javascript engine. If a user were tricked\ninto opening a malicious website, an attacker could exploit this to execute\narbitrary Javascript code within the context of another website or with chrome\nprivileges. (CVE-2008-5511, CVE-2008-5512)\n\nFlaws were discovered in the session-restore feature of Firefox. If a user were\ntricked into opening a malicious website, an attacker could exploit this to\nperform cross-site scripting attacks or execute arbitrary Javascript code with\nchrome privileges. (CVE-2008-5513)\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"firefox","version":"2.0.0.19+nobinonly1-0ubuntu0.7.10.1","description":"","is_source":true},{"name":"firefox","version":"2.0.0.19+nobinonly1-0ubuntu0.7.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/2.0.0.19+nobinonly1-0ubuntu0.7.10.1"}]},"type":"USN","cves_ids":["CVE-2008-5510","CVE-2008-5504","CVE-2008-5508","CVE-2008-5513","CVE-2008-5500","CVE-2008-5503","CVE-2008-5506","CVE-2008-5507","CVE-2008-5511","CVE-2008-5512"]},{"id":"USN-701-1","title":"Thunderbird vulnerabilities","summary":"Thunderbird vulnerabilities","instructions":"After a standard system upgrade you need to restart Thunderbird to effect\nthe necessary changes.\n","references":[],"published":"2009-01-06T23:17:08.901828","description":"Several flaws were discovered in the browser engine. If a user had Javascript\nenabled, these problems could allow an attacker to crash Thunderbird and\npossibly execute arbitrary code with user privileges. (CVE-2008-5500)\n\nBoris Zbarsky discovered that the same-origin check in Thunderbird could be\nbypassed by utilizing XBL-bindings. If a user had Javascript enabled, an\nattacker could exploit this to read data from other domains. (CVE-2008-5503)\n\nMarius Schilder discovered that Thunderbird did not properly handle redirects\nto an outside domain when an XMLHttpRequest was made to a same-origin resource.\nWhen Javascript is enabled, it's possible that sensitive information could be\nrevealed in the XMLHttpRequest response. (CVE-2008-5506)\n\nChris Evans discovered that Thunderbird did not properly protect a user's data\nwhen accessing a same-domain Javascript URL that is redirected to an unparsable\nJavascript off-site resource. If a user were tricked into opening a malicious\nwebsite and had Javascript enabled, an attacker may be able to steal a limited\namount of private data. (CVE-2008-5507)\n\nChip Salzenberg, Justin Schuh, Tom Cross, and Peter William discovered\nThunderbird did not properly parse URLs when processing certain control\ncharacters. (CVE-2008-5508)\n\nKojima Hajime discovered that Thunderbird did not properly handle an escaped\nnull character. An attacker may be able to exploit this flaw to bypass script\nsanitization. (CVE-2008-5510)\n\nSeveral flaws were discovered in the Javascript engine. If a user were tricked\ninto opening a malicious website and had Javascript enabled, an attacker could\nexploit this to execute arbitrary Javascript code within the context of another\nwebsite or with chrome privileges. (CVE-2008-5511, CVE-2008-5512)\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"thunderbird","version":"2.0.0.19+nobinonly-0ubuntu0.7.10.1","description":"","is_source":true},{"name":"thunderbird","version":"2.0.0.19+nobinonly-0ubuntu0.7.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/2.0.0.19+nobinonly-0ubuntu0.7.10.1"}],"intrepid":[{"name":"thunderbird","version":"2.0.0.19+nobinonly-0ubuntu0.8.10.1","description":"","is_source":true},{"name":"thunderbird","version":"2.0.0.19+nobinonly-0ubuntu0.8.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/2.0.0.19+nobinonly-0ubuntu0.8.10.1"}],"hardy":[{"name":"thunderbird","version":"2.0.0.19+nobinonly-0ubuntu0.8.04.1","description":"","is_source":true},{"name":"thunderbird","version":"2.0.0.19+nobinonly-0ubuntu0.8.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/2.0.0.19+nobinonly-0ubuntu0.8.04.1"}]},"type":"USN","cves_ids":["CVE-2008-5500","CVE-2008-5503","CVE-2008-5506","CVE-2008-5507","CVE-2008-5508","CVE-2008-5510","CVE-2008-5511","CVE-2008-5512"]}]},{"id":"CVE-2008-5508","published":"2008-12-17T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x\nbefore 2.0.0.19, and SeaMonkey 1.x before 1.1.14 does not properly parse\nURLs with leading whitespace or control characters, which might allow\nremote attackers to misrepresent URLs and simplify phishing attacks.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-690-2","https://ubuntu.com/security/notices/USN-690-1","https://ubuntu.com/security/notices/USN-701-1","https://ubuntu.com/security/notices/USN-701-2","https://www.cve.org/CVERecord?id=CVE-2008-5508"],"bugs":[""],"patches":{"firefox":[],"firefox-3.0":[],"xulrunner":[],"xulrunner-1.9":[],"seamonkey":[],"iceape":[],"thunderbird":[],"mozilla-thunderbird":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"dapper","status":"released","description":"1.5.dfsg+1.5.0.15~prepatch080614i-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"2.0.0.19+nobinonly1-0ubuntu0.7.10.1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.0.0.19+nobinonly1-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"3.0.5+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"3.0.5+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"3.0.5+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.0.0.19","component":null,"pocket":"security"}]},{"name":"firefox-3.0","source":"https://ubuntu.com/security/cve?package=firefox-3.0","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=firefox-3.0","debian":"https://tracker.debian.org/pkg/firefox-3.0","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"3.0.5+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"3.0.5+nobinonly-0ubuntu0.8.10.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"3.0.5+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.0.5","component":null,"pocket":"security"}]},{"name":"iceape","source":"https://ubuntu.com/security/cve?package=iceape","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=iceape","debian":"https://tracker.debian.org/pkg/iceape","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.1.14","component":null,"pocket":"security"}]},{"name":"mozilla-thunderbird","source":"https://ubuntu.com/security/cve?package=mozilla-thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mozilla-thunderbird","debian":"https://tracker.debian.org/pkg/mozilla-thunderbird","statuses":[{"release_codename":"dapper","status":"released","description":"1.5.0.13+1.5.0.15~prepatch080614i-0ubuntu0.6.06.1","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"seamonkey","source":"https://ubuntu.com/security/cve?package=seamonkey","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=seamonkey","debian":"https://tracker.debian.org/pkg/seamonkey","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.1.15+nobinonly-0ubuntu0.8.04.2","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.1.15+nobinonly-0ubuntu0.8.10.2","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.1.15+nobinonly-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1.1.15+nobinonly-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"1.1.15+nobinonly-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"1.1.15+nobinonly-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"1.1.15+nobinonly-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.1.14","component":null,"pocket":"security"}]},{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"2.0.0.19+nobinonly-0ubuntu0.7.10.1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.0.0.19+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"2.0.0.19+nobinonly-0ubuntu0.8.10.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.0.0.19+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.0.0.19+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.0.0.19+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"2.0.0.19+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"2.0.0.19+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.0.0.19","component":null,"pocket":"security"}]},{"name":"xulrunner","source":"https://ubuntu.com/security/cve?package=xulrunner","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=xulrunner","debian":"https://tracker.debian.org/pkg/xulrunner","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"1.8.1.18+nobinonly.b308.cvs20090331t155113-0ubuntu0.7.10.1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.8.1.18+nobinonly.b308.cvs20090331t155113-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.8.1.18+nobinonly.b308.cvs20090331t155113-0ubuntu0.8.10.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"xulrunner-1.9","source":"https://ubuntu.com/security/cve?package=xulrunner-1.9","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=xulrunner-1.9","debian":"https://tracker.debian.org/pkg/xulrunner-1.9","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.9.0.5+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.9.0.5+nobinonly-0ubuntu0.8.10.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.9.0.5+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-690-1","USN-690-2","USN-701-1","USN-701-2"],"notices":[{"id":"USN-690-1","title":"Firefox and xulrunner vulnerabilities","summary":"Firefox and xulrunner vulnerabilities","instructions":"After a standard system upgrade you need to restart Firefox and any\napplications that use xulrunner, such as Epiphany, to effect the necessary\nchanges.\n","references":[],"published":"2008-12-17T23:50:57.166327","description":"Several flaws were discovered in the browser engine. These problems could allow\nan attacker to crash the browser and possibly execute arbitrary code with user\nprivileges. (CVE-2008-5500, CVE-2008-5501, CVE-2008-5502)\n\nIt was discovered that Firefox did not properly handle persistent cookie data.\nIf a user were tricked into opening a malicious website, an attacker could\nwrite persistent data in the user's browser and track the user across browsing\nsessions. (CVE-2008-5505)\n\nMarius Schilder discovered that Firefox did not properly handle redirects to\nan outside domain when an XMLHttpRequest was made to a same-origin resource.\nIt's possible that sensitive information could be revealed in the\nXMLHttpRequest response. (CVE-2008-5506)\n\nChris Evans discovered that Firefox did not properly protect a user's data when\naccessing a same-domain Javascript URL that is redirected to an unparsable\nJavascript off-site resource. If a user were tricked into opening a malicious\nwebsite, an attacker may be able to steal a limited amount of private data.\n(CVE-2008-5507)\n\nChip Salzenberg, Justin Schuh, Tom Cross, and Peter William discovered Firefox\ndid not properly parse URLs when processing certain control characters.\n(CVE-2008-5508)\n\nKojima Hajime discovered that Firefox did not properly handle an escaped null\ncharacter. An attacker may be able to exploit this flaw to bypass script\nsanitization. (CVE-2008-5510)\n\nSeveral flaws were discovered in the Javascript engine. If a user were tricked\ninto opening a malicious website, an attacker could exploit this to execute\narbitrary Javascript code within the context of another website or with chrome\nprivileges. (CVE-2008-5511, CVE-2008-5512)\n\nFlaws were discovered in the session-restore feature of Firefox. If a user were\ntricked into opening a malicious website, an attacker could exploit this to\nperform cross-site scripting attacks or execute arbitrary Javascript code with\nchrome privileges. (CVE-2008-5513)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"firefox-3.0","version":"3.0.5+nobinonly-0ubuntu0.8.04.1","description":"","is_source":true},{"name":"xulrunner-1.9","version":"1.9.0.5+nobinonly-0ubuntu0.8.04.1","description":"","is_source":true},{"name":"firefox-3.0","version":"3.0.5+nobinonly-0ubuntu0.8.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.0.5+nobinonly-0ubuntu0.8.04.1"},{"name":"xulrunner-1.9","version":"1.9.0.5+nobinonly-0ubuntu0.8.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9/1.9.0.5+nobinonly-0ubuntu0.8.04.1"}],"intrepid":[{"name":"firefox-3.0","version":"3.0.5+nobinonly-0ubuntu0.8.10.1","description":"","is_source":true},{"name":"xulrunner-1.9","version":"1.9.0.5+nobinonly-0ubuntu0.8.10.1","description":"","is_source":true},{"name":"firefox-3.0","version":"3.0.5+nobinonly-0ubuntu0.8.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.0.5+nobinonly-0ubuntu0.8.10.1"},{"name":"abrowser","version":"3.0.5+nobinonly-0ubuntu0.8.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.0.5+nobinonly-0ubuntu0.8.10.1"},{"name":"xulrunner-1.9","version":"1.9.0.5+nobinonly-0ubuntu0.8.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9/1.9.0.5+nobinonly-0ubuntu0.8.10.1"}]},"type":"USN","cves_ids":["CVE-2008-5502","CVE-2008-5501","CVE-2008-5505","CVE-2008-5500","CVE-2008-5506","CVE-2008-5507","CVE-2008-5508","CVE-2008-5510","CVE-2008-5511","CVE-2008-5512","CVE-2008-5513"]},{"id":"USN-690-2","title":"Firefox vulnerabilities","summary":"Firefox vulnerabilities","instructions":"After a standard system upgrade you need to restart Firefox to effect the\nnecessary changes.\n","references":[],"published":"2008-12-18T00:08:10.708002","description":"Several flaws were discovered in the browser engine. These problems could allow\nan attacker to crash the browser and possibly execute arbitrary code with user\nprivileges. (CVE-2008-5500)\n\nBoris Zbarsky discovered that the same-origin check in Firefox could be\nbypassed by utilizing XBL-bindings. An attacker could exploit this to read data\nfrom other domains. (CVE-2008-5503)\n\nSeveral problems were discovered in the JavaScript engine. An attacker could\nexploit feed preview vulnerabilities to execute scripts from page content with\nchrome privileges. (CVE-2008-5504)\n\nMarius Schilder discovered that Firefox did not properly handle redirects to\nan outside domain when an XMLHttpRequest was made to a same-origin resource.\nIt's possible that sensitive information could be revealed in the\nXMLHttpRequest response. (CVE-2008-5506)\n\nChris Evans discovered that Firefox did not properly protect a user's data when\naccessing a same-domain Javascript URL that is redirected to an unparsable\nJavascript off-site resource. If a user were tricked into opening a malicious\nwebsite, an attacker may be able to steal a limited amount of private data.\n(CVE-2008-5507)\n\nChip Salzenberg, Justin Schuh, Tom Cross, and Peter William discovered Firefox\ndid not properly parse URLs when processing certain control characters.\n(CVE-2008-5508)\n\nKojima Hajime discovered that Firefox did not properly handle an escaped null\ncharacter. An attacker may be able to exploit this flaw to bypass script\nsanitization. (CVE-2008-5510)\n\nSeveral flaws were discovered in the Javascript engine. If a user were tricked\ninto opening a malicious website, an attacker could exploit this to execute\narbitrary Javascript code within the context of another website or with chrome\nprivileges. (CVE-2008-5511, CVE-2008-5512)\n\nFlaws were discovered in the session-restore feature of Firefox. If a user were\ntricked into opening a malicious website, an attacker could exploit this to\nperform cross-site scripting attacks or execute arbitrary Javascript code with\nchrome privileges. (CVE-2008-5513)\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"firefox","version":"2.0.0.19+nobinonly1-0ubuntu0.7.10.1","description":"","is_source":true},{"name":"firefox","version":"2.0.0.19+nobinonly1-0ubuntu0.7.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/2.0.0.19+nobinonly1-0ubuntu0.7.10.1"}]},"type":"USN","cves_ids":["CVE-2008-5510","CVE-2008-5504","CVE-2008-5508","CVE-2008-5513","CVE-2008-5500","CVE-2008-5503","CVE-2008-5506","CVE-2008-5507","CVE-2008-5511","CVE-2008-5512"]},{"id":"USN-701-1","title":"Thunderbird vulnerabilities","summary":"Thunderbird vulnerabilities","instructions":"After a standard system upgrade you need to restart Thunderbird to effect\nthe necessary changes.\n","references":[],"published":"2009-01-06T23:17:08.901828","description":"Several flaws were discovered in the browser engine. If a user had Javascript\nenabled, these problems could allow an attacker to crash Thunderbird and\npossibly execute arbitrary code with user privileges. (CVE-2008-5500)\n\nBoris Zbarsky discovered that the same-origin check in Thunderbird could be\nbypassed by utilizing XBL-bindings. If a user had Javascript enabled, an\nattacker could exploit this to read data from other domains. (CVE-2008-5503)\n\nMarius Schilder discovered that Thunderbird did not properly handle redirects\nto an outside domain when an XMLHttpRequest was made to a same-origin resource.\nWhen Javascript is enabled, it's possible that sensitive information could be\nrevealed in the XMLHttpRequest response. (CVE-2008-5506)\n\nChris Evans discovered that Thunderbird did not properly protect a user's data\nwhen accessing a same-domain Javascript URL that is redirected to an unparsable\nJavascript off-site resource. If a user were tricked into opening a malicious\nwebsite and had Javascript enabled, an attacker may be able to steal a limited\namount of private data. (CVE-2008-5507)\n\nChip Salzenberg, Justin Schuh, Tom Cross, and Peter William discovered\nThunderbird did not properly parse URLs when processing certain control\ncharacters. (CVE-2008-5508)\n\nKojima Hajime discovered that Thunderbird did not properly handle an escaped\nnull character. An attacker may be able to exploit this flaw to bypass script\nsanitization. (CVE-2008-5510)\n\nSeveral flaws were discovered in the Javascript engine. If a user were tricked\ninto opening a malicious website and had Javascript enabled, an attacker could\nexploit this to execute arbitrary Javascript code within the context of another\nwebsite or with chrome privileges. (CVE-2008-5511, CVE-2008-5512)\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"thunderbird","version":"2.0.0.19+nobinonly-0ubuntu0.7.10.1","description":"","is_source":true},{"name":"thunderbird","version":"2.0.0.19+nobinonly-0ubuntu0.7.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/2.0.0.19+nobinonly-0ubuntu0.7.10.1"}],"intrepid":[{"name":"thunderbird","version":"2.0.0.19+nobinonly-0ubuntu0.8.10.1","description":"","is_source":true},{"name":"thunderbird","version":"2.0.0.19+nobinonly-0ubuntu0.8.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/2.0.0.19+nobinonly-0ubuntu0.8.10.1"}],"hardy":[{"name":"thunderbird","version":"2.0.0.19+nobinonly-0ubuntu0.8.04.1","description":"","is_source":true},{"name":"thunderbird","version":"2.0.0.19+nobinonly-0ubuntu0.8.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/2.0.0.19+nobinonly-0ubuntu0.8.04.1"}]},"type":"USN","cves_ids":["CVE-2008-5500","CVE-2008-5503","CVE-2008-5506","CVE-2008-5507","CVE-2008-5508","CVE-2008-5510","CVE-2008-5511","CVE-2008-5512"]},{"id":"USN-701-2","title":"Thunderbird vulnerabilities","summary":"Thunderbird vulnerabilities","instructions":"After a standard system upgrade you need to restart Thunderbird to effect\nthe necessary changes.\n","references":[],"published":"2009-01-06T23:31:22.903118","description":"Several flaws were discovered in the browser engine. If a user had Javascript\nenabled, these problems could allow an attacker to crash Thunderbird and\npossibly execute arbitrary code with user privileges. (CVE-2008-5500)\n\nBoris Zbarsky discovered that the same-origin check in Thunderbird could be\nbypassed by utilizing XBL-bindings. If a user had Javascript enabled, an\nattacker could exploit this to read data from other domains. (CVE-2008-5503)\n\nMarius Schilder discovered that Thunderbird did not properly handle redirects\nto an outside domain when an XMLHttpRequest was made to a same-origin resource.\nWhen Javascript is enabled, it's possible that sensitive information could be\nrevealed in the XMLHttpRequest response. (CVE-2008-5506)\n\nChris Evans discovered that Thunderbird did not properly protect a user's data\nwhen accessing a same-domain Javascript URL that is redirected to an unparsable\nJavascript off-site resource. If a user were tricked into opening a malicious\nwebsite and had Javascript enabled, an attacker may be able to steal a limited\namount of private data. (CVE-2008-5507)\n\nChip Salzenberg, Justin Schuh, Tom Cross, and Peter William discovered\nThunderbird did not properly parse URLs when processing certain control\ncharacters. (CVE-2008-5508)\n\nSeveral flaws were discovered in the Javascript engine. If a user were tricked\ninto opening a malicious website and had Javascript enabled, an attacker could\nexploit this to execute arbitrary Javascript code within the context of another\nwebsite or with chrome privileges. (CVE-2008-5511, CVE-2008-5512)\n","is_hidden":false,"release_packages":{"dapper":[{"name":"mozilla-thunderbird","version":"1.5.0.13+1.5.0.15~prepatch080614i-0ubuntu0.6.06.1","description":"","is_source":true},{"name":"mozilla-thunderbird","version":"1.5.0.13+1.5.0.15~prepatch080614i-0ubuntu0.6.06.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/mozilla-thunderbird","version_link":"https://launchpad.net/ubuntu/+source/mozilla-thunderbird/1.5.0.13+1.5.0.15~prepatch080614i-0ubuntu0.6.06.1"}]},"type":"USN","cves_ids":["CVE-2008-5500","CVE-2008-5503","CVE-2008-5506","CVE-2008-5507","CVE-2008-5508","CVE-2008-5511","CVE-2008-5512"]}]},{"id":"CVE-2008-5507","published":"2008-12-17T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x\nbefore 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allow remote attackers to\nbypass the same origin policy and access portions of data from another\ndomain via a JavaScript URL that redirects to the target resource, which\ngenerates an error if the target data does not have JavaScript syntax,\nwhich can be accessed using the window.onerror DOM API.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-690-3","https://ubuntu.com/security/notices/USN-690-2","https://ubuntu.com/security/notices/USN-690-1","https://ubuntu.com/security/notices/USN-701-1","https://ubuntu.com/security/notices/USN-701-2","https://www.cve.org/CVERecord?id=CVE-2008-5507"],"bugs":[""],"patches":{"firefox":[],"firefox-3.0":[],"iceweasel":[],"xulrunner":[],"xulrunner-1.9":[],"seamonkey":[],"iceape":[],"thunderbird":[],"mozilla-thunderbird":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"dapper","status":"released","description":"1.5.dfsg+1.5.0.15~prepatch080614i-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"2.0.0.19+nobinonly1-0ubuntu0.7.10.1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.0.0.19+nobinonly1-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"3.0.5+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"3.0.5+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"3.0.5+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.0.0.19","component":null,"pocket":"security"}]},{"name":"firefox-3.0","source":"https://ubuntu.com/security/cve?package=firefox-3.0","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=firefox-3.0","debian":"https://tracker.debian.org/pkg/firefox-3.0","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"3.0.5+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"3.0.5+nobinonly-0ubuntu0.8.10.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"3.0.5+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.0.5","component":null,"pocket":"security"}]},{"name":"iceape","source":"https://ubuntu.com/security/cve?package=iceape","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=iceape","debian":"https://tracker.debian.org/pkg/iceape","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.1.14","component":null,"pocket":"security"}]},{"name":"iceweasel","source":"https://ubuntu.com/security/cve?package=iceweasel","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=iceweasel","debian":"https://tracker.debian.org/pkg/iceweasel","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.0.0.19","component":null,"pocket":"security"}]},{"name":"mozilla-thunderbird","source":"https://ubuntu.com/security/cve?package=mozilla-thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mozilla-thunderbird","debian":"https://tracker.debian.org/pkg/mozilla-thunderbird","statuses":[{"release_codename":"dapper","status":"released","description":"1.5.0.13+1.5.0.15~prepatch080614i-0ubuntu0.6.06.1","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"seamonkey","source":"https://ubuntu.com/security/cve?package=seamonkey","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=seamonkey","debian":"https://tracker.debian.org/pkg/seamonkey","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.1.15+nobinonly-0ubuntu0.8.04.2","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.1.15+nobinonly-0ubuntu0.8.10.2","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.1.15+nobinonly-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1.1.15+nobinonly-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"1.1.15+nobinonly-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"1.1.15+nobinonly-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"1.1.15+nobinonly-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.1.14","component":null,"pocket":"security"}]},{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"2.0.0.19+nobinonly-0ubuntu0.7.10.1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.0.0.19+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"2.0.0.19+nobinonly-0ubuntu0.8.10.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.0.0.19+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.0.0.19+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.0.0.19+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"2.0.0.19+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"2.0.0.19+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.0.0.19","component":null,"pocket":"security"}]},{"name":"xulrunner","source":"https://ubuntu.com/security/cve?package=xulrunner","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=xulrunner","debian":"https://tracker.debian.org/pkg/xulrunner","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"1.8.1.18+nobinonly.b308.cvs20090331t155113-0ubuntu0.7.10.1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.8.1.18+nobinonly.b308.cvs20090331t155113-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.8.1.18+nobinonly.b308.cvs20090331t155113-0ubuntu0.8.10.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"xulrunner-1.9","source":"https://ubuntu.com/security/cve?package=xulrunner-1.9","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=xulrunner-1.9","debian":"https://tracker.debian.org/pkg/xulrunner-1.9","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.9.0.5+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.9.0.5+nobinonly-0ubuntu0.8.10.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.9.0.5+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-690-1","USN-690-3","USN-690-2","USN-701-1","USN-701-2"],"notices":[{"id":"USN-690-1","title":"Firefox and xulrunner vulnerabilities","summary":"Firefox and xulrunner vulnerabilities","instructions":"After a standard system upgrade you need to restart Firefox and any\napplications that use xulrunner, such as Epiphany, to effect the necessary\nchanges.\n","references":[],"published":"2008-12-17T23:50:57.166327","description":"Several flaws were discovered in the browser engine. These problems could allow\nan attacker to crash the browser and possibly execute arbitrary code with user\nprivileges. (CVE-2008-5500, CVE-2008-5501, CVE-2008-5502)\n\nIt was discovered that Firefox did not properly handle persistent cookie data.\nIf a user were tricked into opening a malicious website, an attacker could\nwrite persistent data in the user's browser and track the user across browsing\nsessions. (CVE-2008-5505)\n\nMarius Schilder discovered that Firefox did not properly handle redirects to\nan outside domain when an XMLHttpRequest was made to a same-origin resource.\nIt's possible that sensitive information could be revealed in the\nXMLHttpRequest response. (CVE-2008-5506)\n\nChris Evans discovered that Firefox did not properly protect a user's data when\naccessing a same-domain Javascript URL that is redirected to an unparsable\nJavascript off-site resource. If a user were tricked into opening a malicious\nwebsite, an attacker may be able to steal a limited amount of private data.\n(CVE-2008-5507)\n\nChip Salzenberg, Justin Schuh, Tom Cross, and Peter William discovered Firefox\ndid not properly parse URLs when processing certain control characters.\n(CVE-2008-5508)\n\nKojima Hajime discovered that Firefox did not properly handle an escaped null\ncharacter. An attacker may be able to exploit this flaw to bypass script\nsanitization. (CVE-2008-5510)\n\nSeveral flaws were discovered in the Javascript engine. If a user were tricked\ninto opening a malicious website, an attacker could exploit this to execute\narbitrary Javascript code within the context of another website or with chrome\nprivileges. (CVE-2008-5511, CVE-2008-5512)\n\nFlaws were discovered in the session-restore feature of Firefox. If a user were\ntricked into opening a malicious website, an attacker could exploit this to\nperform cross-site scripting attacks or execute arbitrary Javascript code with\nchrome privileges. (CVE-2008-5513)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"firefox-3.0","version":"3.0.5+nobinonly-0ubuntu0.8.04.1","description":"","is_source":true},{"name":"xulrunner-1.9","version":"1.9.0.5+nobinonly-0ubuntu0.8.04.1","description":"","is_source":true},{"name":"firefox-3.0","version":"3.0.5+nobinonly-0ubuntu0.8.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.0.5+nobinonly-0ubuntu0.8.04.1"},{"name":"xulrunner-1.9","version":"1.9.0.5+nobinonly-0ubuntu0.8.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9/1.9.0.5+nobinonly-0ubuntu0.8.04.1"}],"intrepid":[{"name":"firefox-3.0","version":"3.0.5+nobinonly-0ubuntu0.8.10.1","description":"","is_source":true},{"name":"xulrunner-1.9","version":"1.9.0.5+nobinonly-0ubuntu0.8.10.1","description":"","is_source":true},{"name":"firefox-3.0","version":"3.0.5+nobinonly-0ubuntu0.8.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.0.5+nobinonly-0ubuntu0.8.10.1"},{"name":"abrowser","version":"3.0.5+nobinonly-0ubuntu0.8.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.0.5+nobinonly-0ubuntu0.8.10.1"},{"name":"xulrunner-1.9","version":"1.9.0.5+nobinonly-0ubuntu0.8.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9/1.9.0.5+nobinonly-0ubuntu0.8.10.1"}]},"type":"USN","cves_ids":["CVE-2008-5502","CVE-2008-5501","CVE-2008-5505","CVE-2008-5500","CVE-2008-5506","CVE-2008-5507","CVE-2008-5508","CVE-2008-5510","CVE-2008-5511","CVE-2008-5512","CVE-2008-5513"]},{"id":"USN-690-3","title":"Firefox vulnerabilities","summary":"Firefox vulnerabilities","instructions":"After a standard system upgrade you need to restart Firefox to effect the\nnecessary changes.\n","references":[],"published":"2008-12-18T00:17:53.636632","description":"Several flaws were discovered in the browser engine. These problems could allow\nan attacker to crash the browser and possibly execute arbitrary code with user\nprivileges. (CVE-2008-5500)\n\nBoris Zbarsky discovered that the same-origin check in Firefox could be\nbypassed by utilizing XBL-bindings. An attacker could exploit this to read data\nfrom other domains. (CVE-2008-5503)\n\nMarius Schilder discovered that Firefox did not properly handle redirects to\nan outside domain when an XMLHttpRequest was made to a same-origin resource.\nIt's possible that sensitive information could be revealed in the\nXMLHttpRequest response. (CVE-2008-5506)\n\nChris Evans discovered that Firefox did not properly protect a user's data when\naccessing a same-domain Javascript URL that is redirected to an unparsable\nJavascript off-site resource. If a user were tricked into opening a malicious\nwebsite, an attacker may be able to steal a limited amount of private data.\n(CVE-2008-5507)\n\nSeveral flaws were discovered in the Javascript engine. If a user were tricked\ninto opening a malicious website, an attacker could exploit this to execute\narbitrary Javascript code within the context of another website or with chrome\nprivileges. (CVE-2008-5511, CVE-2008-5512)\n","is_hidden":false,"release_packages":{"dapper":[{"name":"firefox","version":"1.5.dfsg+1.5.0.15~prepatch080614i-0ubuntu1","description":"","is_source":true},{"name":"firefox","version":"1.5.dfsg+1.5.0.15~prepatch080614i-0ubuntu1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/1.5.dfsg+1.5.0.15~prepatch080614i-0ubuntu1"}]},"type":"USN","cves_ids":["CVE-2008-5503","CVE-2008-5507","CVE-2008-5512","CVE-2008-5511","CVE-2008-5500","CVE-2008-5506"]},{"id":"USN-690-2","title":"Firefox vulnerabilities","summary":"Firefox vulnerabilities","instructions":"After a standard system upgrade you need to restart Firefox to effect the\nnecessary changes.\n","references":[],"published":"2008-12-18T00:08:10.708002","description":"Several flaws were discovered in the browser engine. These problems could allow\nan attacker to crash the browser and possibly execute arbitrary code with user\nprivileges. (CVE-2008-5500)\n\nBoris Zbarsky discovered that the same-origin check in Firefox could be\nbypassed by utilizing XBL-bindings. An attacker could exploit this to read data\nfrom other domains. (CVE-2008-5503)\n\nSeveral problems were discovered in the JavaScript engine. An attacker could\nexploit feed preview vulnerabilities to execute scripts from page content with\nchrome privileges. (CVE-2008-5504)\n\nMarius Schilder discovered that Firefox did not properly handle redirects to\nan outside domain when an XMLHttpRequest was made to a same-origin resource.\nIt's possible that sensitive information could be revealed in the\nXMLHttpRequest response. (CVE-2008-5506)\n\nChris Evans discovered that Firefox did not properly protect a user's data when\naccessing a same-domain Javascript URL that is redirected to an unparsable\nJavascript off-site resource. If a user were tricked into opening a malicious\nwebsite, an attacker may be able to steal a limited amount of private data.\n(CVE-2008-5507)\n\nChip Salzenberg, Justin Schuh, Tom Cross, and Peter William discovered Firefox\ndid not properly parse URLs when processing certain control characters.\n(CVE-2008-5508)\n\nKojima Hajime discovered that Firefox did not properly handle an escaped null\ncharacter. An attacker may be able to exploit this flaw to bypass script\nsanitization. (CVE-2008-5510)\n\nSeveral flaws were discovered in the Javascript engine. If a user were tricked\ninto opening a malicious website, an attacker could exploit this to execute\narbitrary Javascript code within the context of another website or with chrome\nprivileges. (CVE-2008-5511, CVE-2008-5512)\n\nFlaws were discovered in the session-restore feature of Firefox. If a user were\ntricked into opening a malicious website, an attacker could exploit this to\nperform cross-site scripting attacks or execute arbitrary Javascript code with\nchrome privileges. (CVE-2008-5513)\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"firefox","version":"2.0.0.19+nobinonly1-0ubuntu0.7.10.1","description":"","is_source":true},{"name":"firefox","version":"2.0.0.19+nobinonly1-0ubuntu0.7.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/2.0.0.19+nobinonly1-0ubuntu0.7.10.1"}]},"type":"USN","cves_ids":["CVE-2008-5510","CVE-2008-5504","CVE-2008-5508","CVE-2008-5513","CVE-2008-5500","CVE-2008-5503","CVE-2008-5506","CVE-2008-5507","CVE-2008-5511","CVE-2008-5512"]},{"id":"USN-701-1","title":"Thunderbird vulnerabilities","summary":"Thunderbird vulnerabilities","instructions":"After a standard system upgrade you need to restart Thunderbird to effect\nthe necessary changes.\n","references":[],"published":"2009-01-06T23:17:08.901828","description":"Several flaws were discovered in the browser engine. If a user had Javascript\nenabled, these problems could allow an attacker to crash Thunderbird and\npossibly execute arbitrary code with user privileges. (CVE-2008-5500)\n\nBoris Zbarsky discovered that the same-origin check in Thunderbird could be\nbypassed by utilizing XBL-bindings. If a user had Javascript enabled, an\nattacker could exploit this to read data from other domains. (CVE-2008-5503)\n\nMarius Schilder discovered that Thunderbird did not properly handle redirects\nto an outside domain when an XMLHttpRequest was made to a same-origin resource.\nWhen Javascript is enabled, it's possible that sensitive information could be\nrevealed in the XMLHttpRequest response. (CVE-2008-5506)\n\nChris Evans discovered that Thunderbird did not properly protect a user's data\nwhen accessing a same-domain Javascript URL that is redirected to an unparsable\nJavascript off-site resource. If a user were tricked into opening a malicious\nwebsite and had Javascript enabled, an attacker may be able to steal a limited\namount of private data. (CVE-2008-5507)\n\nChip Salzenberg, Justin Schuh, Tom Cross, and Peter William discovered\nThunderbird did not properly parse URLs when processing certain control\ncharacters. (CVE-2008-5508)\n\nKojima Hajime discovered that Thunderbird did not properly handle an escaped\nnull character. An attacker may be able to exploit this flaw to bypass script\nsanitization. (CVE-2008-5510)\n\nSeveral flaws were discovered in the Javascript engine. If a user were tricked\ninto opening a malicious website and had Javascript enabled, an attacker could\nexploit this to execute arbitrary Javascript code within the context of another\nwebsite or with chrome privileges. (CVE-2008-5511, CVE-2008-5512)\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"thunderbird","version":"2.0.0.19+nobinonly-0ubuntu0.7.10.1","description":"","is_source":true},{"name":"thunderbird","version":"2.0.0.19+nobinonly-0ubuntu0.7.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/2.0.0.19+nobinonly-0ubuntu0.7.10.1"}],"intrepid":[{"name":"thunderbird","version":"2.0.0.19+nobinonly-0ubuntu0.8.10.1","description":"","is_source":true},{"name":"thunderbird","version":"2.0.0.19+nobinonly-0ubuntu0.8.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/2.0.0.19+nobinonly-0ubuntu0.8.10.1"}],"hardy":[{"name":"thunderbird","version":"2.0.0.19+nobinonly-0ubuntu0.8.04.1","description":"","is_source":true},{"name":"thunderbird","version":"2.0.0.19+nobinonly-0ubuntu0.8.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/2.0.0.19+nobinonly-0ubuntu0.8.04.1"}]},"type":"USN","cves_ids":["CVE-2008-5500","CVE-2008-5503","CVE-2008-5506","CVE-2008-5507","CVE-2008-5508","CVE-2008-5510","CVE-2008-5511","CVE-2008-5512"]},{"id":"USN-701-2","title":"Thunderbird vulnerabilities","summary":"Thunderbird vulnerabilities","instructions":"After a standard system upgrade you need to restart Thunderbird to effect\nthe necessary changes.\n","references":[],"published":"2009-01-06T23:31:22.903118","description":"Several flaws were discovered in the browser engine. If a user had Javascript\nenabled, these problems could allow an attacker to crash Thunderbird and\npossibly execute arbitrary code with user privileges. (CVE-2008-5500)\n\nBoris Zbarsky discovered that the same-origin check in Thunderbird could be\nbypassed by utilizing XBL-bindings. If a user had Javascript enabled, an\nattacker could exploit this to read data from other domains. (CVE-2008-5503)\n\nMarius Schilder discovered that Thunderbird did not properly handle redirects\nto an outside domain when an XMLHttpRequest was made to a same-origin resource.\nWhen Javascript is enabled, it's possible that sensitive information could be\nrevealed in the XMLHttpRequest response. (CVE-2008-5506)\n\nChris Evans discovered that Thunderbird did not properly protect a user's data\nwhen accessing a same-domain Javascript URL that is redirected to an unparsable\nJavascript off-site resource. If a user were tricked into opening a malicious\nwebsite and had Javascript enabled, an attacker may be able to steal a limited\namount of private data. (CVE-2008-5507)\n\nChip Salzenberg, Justin Schuh, Tom Cross, and Peter William discovered\nThunderbird did not properly parse URLs when processing certain control\ncharacters. (CVE-2008-5508)\n\nSeveral flaws were discovered in the Javascript engine. If a user were tricked\ninto opening a malicious website and had Javascript enabled, an attacker could\nexploit this to execute arbitrary Javascript code within the context of another\nwebsite or with chrome privileges. (CVE-2008-5511, CVE-2008-5512)\n","is_hidden":false,"release_packages":{"dapper":[{"name":"mozilla-thunderbird","version":"1.5.0.13+1.5.0.15~prepatch080614i-0ubuntu0.6.06.1","description":"","is_source":true},{"name":"mozilla-thunderbird","version":"1.5.0.13+1.5.0.15~prepatch080614i-0ubuntu0.6.06.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/mozilla-thunderbird","version_link":"https://launchpad.net/ubuntu/+source/mozilla-thunderbird/1.5.0.13+1.5.0.15~prepatch080614i-0ubuntu0.6.06.1"}]},"type":"USN","cves_ids":["CVE-2008-5500","CVE-2008-5503","CVE-2008-5506","CVE-2008-5507","CVE-2008-5508","CVE-2008-5511","CVE-2008-5512"]}]},{"id":"CVE-2008-5506","published":"2008-12-17T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x\nbefore 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to\nbypass the same origin policy by causing the browser to issue an\nXMLHttpRequest to an attacker-controlled resource that uses a 302 redirect\nto a resource in a different domain, then reading content from the\nresponse, aka \"response disclosure.\"","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-690-3","https://ubuntu.com/security/notices/USN-690-2","https://ubuntu.com/security/notices/USN-690-1","https://ubuntu.com/security/notices/USN-701-1","https://ubuntu.com/security/notices/USN-701-2","https://www.cve.org/CVERecord?id=CVE-2008-5506"],"bugs":[""],"patches":{"firefox":[],"firefox-3.0":[],"xulrunner":[],"xulrunner-1.9":[],"seamonkey":[],"iceape":[],"thunderbird":[],"mozilla-thunderbird":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"dapper","status":"released","description":"1.5.dfsg+1.5.0.15~prepatch080614i-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"2.0.0.19+nobinonly1-0ubuntu0.7.10.1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.0.0.19+nobinonly1-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"3.0.5+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"3.0.5+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"3.0.5+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.0.0.19","component":null,"pocket":"security"}]},{"name":"firefox-3.0","source":"https://ubuntu.com/security/cve?package=firefox-3.0","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=firefox-3.0","debian":"https://tracker.debian.org/pkg/firefox-3.0","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"3.0.5+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"3.0.5+nobinonly-0ubuntu0.8.10.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"3.0.5+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.0.5","component":null,"pocket":"security"}]},{"name":"iceape","source":"https://ubuntu.com/security/cve?package=iceape","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=iceape","debian":"https://tracker.debian.org/pkg/iceape","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.1.14","component":null,"pocket":"security"}]},{"name":"mozilla-thunderbird","source":"https://ubuntu.com/security/cve?package=mozilla-thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mozilla-thunderbird","debian":"https://tracker.debian.org/pkg/mozilla-thunderbird","statuses":[{"release_codename":"dapper","status":"released","description":"1.5.0.13+1.5.0.15~prepatch080614i-0ubuntu0.6.06.1","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"seamonkey","source":"https://ubuntu.com/security/cve?package=seamonkey","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=seamonkey","debian":"https://tracker.debian.org/pkg/seamonkey","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.1.15+nobinonly-0ubuntu0.8.04.2","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.1.15+nobinonly-0ubuntu0.8.10.2","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.1.15+nobinonly-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1.1.15+nobinonly-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"1.1.15+nobinonly-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"1.1.15+nobinonly-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"1.1.15+nobinonly-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.1.14","component":null,"pocket":"security"}]},{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"2.0.0.19+nobinonly-0ubuntu0.7.10.1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.0.0.19+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"2.0.0.19+nobinonly-0ubuntu0.8.10.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.0.0.19+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.0.0.19+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.0.0.19+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"2.0.0.19+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"2.0.0.19+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.0.0.19","component":null,"pocket":"security"}]},{"name":"xulrunner","source":"https://ubuntu.com/security/cve?package=xulrunner","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=xulrunner","debian":"https://tracker.debian.org/pkg/xulrunner","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"1.8.1.18+nobinonly.b308.cvs20090331t155113-0ubuntu0.7.10.1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.8.1.18+nobinonly.b308.cvs20090331t155113-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.8.1.18+nobinonly.b308.cvs20090331t155113-0ubuntu0.8.10.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"xulrunner-1.9","source":"https://ubuntu.com/security/cve?package=xulrunner-1.9","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=xulrunner-1.9","debian":"https://tracker.debian.org/pkg/xulrunner-1.9","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.9.0.5+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.9.0.5+nobinonly-0ubuntu0.8.10.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.9.0.5+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-690-1","USN-690-3","USN-690-2","USN-701-1","USN-701-2"],"notices":[{"id":"USN-690-1","title":"Firefox and xulrunner vulnerabilities","summary":"Firefox and xulrunner vulnerabilities","instructions":"After a standard system upgrade you need to restart Firefox and any\napplications that use xulrunner, such as Epiphany, to effect the necessary\nchanges.\n","references":[],"published":"2008-12-17T23:50:57.166327","description":"Several flaws were discovered in the browser engine. These problems could allow\nan attacker to crash the browser and possibly execute arbitrary code with user\nprivileges. (CVE-2008-5500, CVE-2008-5501, CVE-2008-5502)\n\nIt was discovered that Firefox did not properly handle persistent cookie data.\nIf a user were tricked into opening a malicious website, an attacker could\nwrite persistent data in the user's browser and track the user across browsing\nsessions. (CVE-2008-5505)\n\nMarius Schilder discovered that Firefox did not properly handle redirects to\nan outside domain when an XMLHttpRequest was made to a same-origin resource.\nIt's possible that sensitive information could be revealed in the\nXMLHttpRequest response. (CVE-2008-5506)\n\nChris Evans discovered that Firefox did not properly protect a user's data when\naccessing a same-domain Javascript URL that is redirected to an unparsable\nJavascript off-site resource. If a user were tricked into opening a malicious\nwebsite, an attacker may be able to steal a limited amount of private data.\n(CVE-2008-5507)\n\nChip Salzenberg, Justin Schuh, Tom Cross, and Peter William discovered Firefox\ndid not properly parse URLs when processing certain control characters.\n(CVE-2008-5508)\n\nKojima Hajime discovered that Firefox did not properly handle an escaped null\ncharacter. An attacker may be able to exploit this flaw to bypass script\nsanitization. (CVE-2008-5510)\n\nSeveral flaws were discovered in the Javascript engine. If a user were tricked\ninto opening a malicious website, an attacker could exploit this to execute\narbitrary Javascript code within the context of another website or with chrome\nprivileges. (CVE-2008-5511, CVE-2008-5512)\n\nFlaws were discovered in the session-restore feature of Firefox. If a user were\ntricked into opening a malicious website, an attacker could exploit this to\nperform cross-site scripting attacks or execute arbitrary Javascript code with\nchrome privileges. (CVE-2008-5513)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"firefox-3.0","version":"3.0.5+nobinonly-0ubuntu0.8.04.1","description":"","is_source":true},{"name":"xulrunner-1.9","version":"1.9.0.5+nobinonly-0ubuntu0.8.04.1","description":"","is_source":true},{"name":"firefox-3.0","version":"3.0.5+nobinonly-0ubuntu0.8.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.0.5+nobinonly-0ubuntu0.8.04.1"},{"name":"xulrunner-1.9","version":"1.9.0.5+nobinonly-0ubuntu0.8.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9/1.9.0.5+nobinonly-0ubuntu0.8.04.1"}],"intrepid":[{"name":"firefox-3.0","version":"3.0.5+nobinonly-0ubuntu0.8.10.1","description":"","is_source":true},{"name":"xulrunner-1.9","version":"1.9.0.5+nobinonly-0ubuntu0.8.10.1","description":"","is_source":true},{"name":"firefox-3.0","version":"3.0.5+nobinonly-0ubuntu0.8.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.0.5+nobinonly-0ubuntu0.8.10.1"},{"name":"abrowser","version":"3.0.5+nobinonly-0ubuntu0.8.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.0.5+nobinonly-0ubuntu0.8.10.1"},{"name":"xulrunner-1.9","version":"1.9.0.5+nobinonly-0ubuntu0.8.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9/1.9.0.5+nobinonly-0ubuntu0.8.10.1"}]},"type":"USN","cves_ids":["CVE-2008-5502","CVE-2008-5501","CVE-2008-5505","CVE-2008-5500","CVE-2008-5506","CVE-2008-5507","CVE-2008-5508","CVE-2008-5510","CVE-2008-5511","CVE-2008-5512","CVE-2008-5513"]},{"id":"USN-690-3","title":"Firefox vulnerabilities","summary":"Firefox vulnerabilities","instructions":"After a standard system upgrade you need to restart Firefox to effect the\nnecessary changes.\n","references":[],"published":"2008-12-18T00:17:53.636632","description":"Several flaws were discovered in the browser engine. These problems could allow\nan attacker to crash the browser and possibly execute arbitrary code with user\nprivileges. (CVE-2008-5500)\n\nBoris Zbarsky discovered that the same-origin check in Firefox could be\nbypassed by utilizing XBL-bindings. An attacker could exploit this to read data\nfrom other domains. (CVE-2008-5503)\n\nMarius Schilder discovered that Firefox did not properly handle redirects to\nan outside domain when an XMLHttpRequest was made to a same-origin resource.\nIt's possible that sensitive information could be revealed in the\nXMLHttpRequest response. (CVE-2008-5506)\n\nChris Evans discovered that Firefox did not properly protect a user's data when\naccessing a same-domain Javascript URL that is redirected to an unparsable\nJavascript off-site resource. If a user were tricked into opening a malicious\nwebsite, an attacker may be able to steal a limited amount of private data.\n(CVE-2008-5507)\n\nSeveral flaws were discovered in the Javascript engine. If a user were tricked\ninto opening a malicious website, an attacker could exploit this to execute\narbitrary Javascript code within the context of another website or with chrome\nprivileges. (CVE-2008-5511, CVE-2008-5512)\n","is_hidden":false,"release_packages":{"dapper":[{"name":"firefox","version":"1.5.dfsg+1.5.0.15~prepatch080614i-0ubuntu1","description":"","is_source":true},{"name":"firefox","version":"1.5.dfsg+1.5.0.15~prepatch080614i-0ubuntu1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/1.5.dfsg+1.5.0.15~prepatch080614i-0ubuntu1"}]},"type":"USN","cves_ids":["CVE-2008-5503","CVE-2008-5507","CVE-2008-5512","CVE-2008-5511","CVE-2008-5500","CVE-2008-5506"]},{"id":"USN-690-2","title":"Firefox vulnerabilities","summary":"Firefox vulnerabilities","instructions":"After a standard system upgrade you need to restart Firefox to effect the\nnecessary changes.\n","references":[],"published":"2008-12-18T00:08:10.708002","description":"Several flaws were discovered in the browser engine. These problems could allow\nan attacker to crash the browser and possibly execute arbitrary code with user\nprivileges. (CVE-2008-5500)\n\nBoris Zbarsky discovered that the same-origin check in Firefox could be\nbypassed by utilizing XBL-bindings. An attacker could exploit this to read data\nfrom other domains. (CVE-2008-5503)\n\nSeveral problems were discovered in the JavaScript engine. An attacker could\nexploit feed preview vulnerabilities to execute scripts from page content with\nchrome privileges. (CVE-2008-5504)\n\nMarius Schilder discovered that Firefox did not properly handle redirects to\nan outside domain when an XMLHttpRequest was made to a same-origin resource.\nIt's possible that sensitive information could be revealed in the\nXMLHttpRequest response. (CVE-2008-5506)\n\nChris Evans discovered that Firefox did not properly protect a user's data when\naccessing a same-domain Javascript URL that is redirected to an unparsable\nJavascript off-site resource. If a user were tricked into opening a malicious\nwebsite, an attacker may be able to steal a limited amount of private data.\n(CVE-2008-5507)\n\nChip Salzenberg, Justin Schuh, Tom Cross, and Peter William discovered Firefox\ndid not properly parse URLs when processing certain control characters.\n(CVE-2008-5508)\n\nKojima Hajime discovered that Firefox did not properly handle an escaped null\ncharacter. An attacker may be able to exploit this flaw to bypass script\nsanitization. (CVE-2008-5510)\n\nSeveral flaws were discovered in the Javascript engine. If a user were tricked\ninto opening a malicious website, an attacker could exploit this to execute\narbitrary Javascript code within the context of another website or with chrome\nprivileges. (CVE-2008-5511, CVE-2008-5512)\n\nFlaws were discovered in the session-restore feature of Firefox. If a user were\ntricked into opening a malicious website, an attacker could exploit this to\nperform cross-site scripting attacks or execute arbitrary Javascript code with\nchrome privileges. (CVE-2008-5513)\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"firefox","version":"2.0.0.19+nobinonly1-0ubuntu0.7.10.1","description":"","is_source":true},{"name":"firefox","version":"2.0.0.19+nobinonly1-0ubuntu0.7.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/2.0.0.19+nobinonly1-0ubuntu0.7.10.1"}]},"type":"USN","cves_ids":["CVE-2008-5510","CVE-2008-5504","CVE-2008-5508","CVE-2008-5513","CVE-2008-5500","CVE-2008-5503","CVE-2008-5506","CVE-2008-5507","CVE-2008-5511","CVE-2008-5512"]},{"id":"USN-701-1","title":"Thunderbird vulnerabilities","summary":"Thunderbird vulnerabilities","instructions":"After a standard system upgrade you need to restart Thunderbird to effect\nthe necessary changes.\n","references":[],"published":"2009-01-06T23:17:08.901828","description":"Several flaws were discovered in the browser engine. If a user had Javascript\nenabled, these problems could allow an attacker to crash Thunderbird and\npossibly execute arbitrary code with user privileges. (CVE-2008-5500)\n\nBoris Zbarsky discovered that the same-origin check in Thunderbird could be\nbypassed by utilizing XBL-bindings. If a user had Javascript enabled, an\nattacker could exploit this to read data from other domains. (CVE-2008-5503)\n\nMarius Schilder discovered that Thunderbird did not properly handle redirects\nto an outside domain when an XMLHttpRequest was made to a same-origin resource.\nWhen Javascript is enabled, it's possible that sensitive information could be\nrevealed in the XMLHttpRequest response. (CVE-2008-5506)\n\nChris Evans discovered that Thunderbird did not properly protect a user's data\nwhen accessing a same-domain Javascript URL that is redirected to an unparsable\nJavascript off-site resource. If a user were tricked into opening a malicious\nwebsite and had Javascript enabled, an attacker may be able to steal a limited\namount of private data. (CVE-2008-5507)\n\nChip Salzenberg, Justin Schuh, Tom Cross, and Peter William discovered\nThunderbird did not properly parse URLs when processing certain control\ncharacters. (CVE-2008-5508)\n\nKojima Hajime discovered that Thunderbird did not properly handle an escaped\nnull character. An attacker may be able to exploit this flaw to bypass script\nsanitization. (CVE-2008-5510)\n\nSeveral flaws were discovered in the Javascript engine. If a user were tricked\ninto opening a malicious website and had Javascript enabled, an attacker could\nexploit this to execute arbitrary Javascript code within the context of another\nwebsite or with chrome privileges. (CVE-2008-5511, CVE-2008-5512)\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"thunderbird","version":"2.0.0.19+nobinonly-0ubuntu0.7.10.1","description":"","is_source":true},{"name":"thunderbird","version":"2.0.0.19+nobinonly-0ubuntu0.7.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/2.0.0.19+nobinonly-0ubuntu0.7.10.1"}],"intrepid":[{"name":"thunderbird","version":"2.0.0.19+nobinonly-0ubuntu0.8.10.1","description":"","is_source":true},{"name":"thunderbird","version":"2.0.0.19+nobinonly-0ubuntu0.8.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/2.0.0.19+nobinonly-0ubuntu0.8.10.1"}],"hardy":[{"name":"thunderbird","version":"2.0.0.19+nobinonly-0ubuntu0.8.04.1","description":"","is_source":true},{"name":"thunderbird","version":"2.0.0.19+nobinonly-0ubuntu0.8.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/2.0.0.19+nobinonly-0ubuntu0.8.04.1"}]},"type":"USN","cves_ids":["CVE-2008-5500","CVE-2008-5503","CVE-2008-5506","CVE-2008-5507","CVE-2008-5508","CVE-2008-5510","CVE-2008-5511","CVE-2008-5512"]},{"id":"USN-701-2","title":"Thunderbird vulnerabilities","summary":"Thunderbird vulnerabilities","instructions":"After a standard system upgrade you need to restart Thunderbird to effect\nthe necessary changes.\n","references":[],"published":"2009-01-06T23:31:22.903118","description":"Several flaws were discovered in the browser engine. If a user had Javascript\nenabled, these problems could allow an attacker to crash Thunderbird and\npossibly execute arbitrary code with user privileges. (CVE-2008-5500)\n\nBoris Zbarsky discovered that the same-origin check in Thunderbird could be\nbypassed by utilizing XBL-bindings. If a user had Javascript enabled, an\nattacker could exploit this to read data from other domains. (CVE-2008-5503)\n\nMarius Schilder discovered that Thunderbird did not properly handle redirects\nto an outside domain when an XMLHttpRequest was made to a same-origin resource.\nWhen Javascript is enabled, it's possible that sensitive information could be\nrevealed in the XMLHttpRequest response. (CVE-2008-5506)\n\nChris Evans discovered that Thunderbird did not properly protect a user's data\nwhen accessing a same-domain Javascript URL that is redirected to an unparsable\nJavascript off-site resource. If a user were tricked into opening a malicious\nwebsite and had Javascript enabled, an attacker may be able to steal a limited\namount of private data. (CVE-2008-5507)\n\nChip Salzenberg, Justin Schuh, Tom Cross, and Peter William discovered\nThunderbird did not properly parse URLs when processing certain control\ncharacters. (CVE-2008-5508)\n\nSeveral flaws were discovered in the Javascript engine. If a user were tricked\ninto opening a malicious website and had Javascript enabled, an attacker could\nexploit this to execute arbitrary Javascript code within the context of another\nwebsite or with chrome privileges. (CVE-2008-5511, CVE-2008-5512)\n","is_hidden":false,"release_packages":{"dapper":[{"name":"mozilla-thunderbird","version":"1.5.0.13+1.5.0.15~prepatch080614i-0ubuntu0.6.06.1","description":"","is_source":true},{"name":"mozilla-thunderbird","version":"1.5.0.13+1.5.0.15~prepatch080614i-0ubuntu0.6.06.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/mozilla-thunderbird","version_link":"https://launchpad.net/ubuntu/+source/mozilla-thunderbird/1.5.0.13+1.5.0.15~prepatch080614i-0ubuntu0.6.06.1"}]},"type":"USN","cves_ids":["CVE-2008-5500","CVE-2008-5503","CVE-2008-5506","CVE-2008-5507","CVE-2008-5508","CVE-2008-5511","CVE-2008-5512"]}]},{"id":"CVE-2008-5503","published":"2008-12-17T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe loadBindingDocument function in Mozilla Firefox 2.x before 2.0.0.19,\nThunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 does not\nperform any security checks related to the same-domain policy, which allows\nremote attackers to read or access data from other domains via crafted XBL\nbindings.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-690-3","https://ubuntu.com/security/notices/USN-690-2","https://ubuntu.com/security/notices/USN-701-1","https://ubuntu.com/security/notices/USN-701-2","https://www.cve.org/CVERecord?id=CVE-2008-5503"],"bugs":[""],"patches":{"firefox-3.0":[],"firefox":[],"xulrunner-1.9":[],"seamonkey":[],"iceape":[],"thunderbird":[],"mozilla-thunderbird":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"dapper","status":"released","description":"1.5.dfsg+1.5.0.15~prepatch080614i-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"2.0.0.19+nobinonly1-0ubuntu0.7.10.1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.0.0.21~tb.21.308+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"firefox-3.0","source":"https://ubuntu.com/security/cve?package=firefox-3.0","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=firefox-3.0","debian":"https://tracker.debian.org/pkg/firefox-3.0","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"3.0.5+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"3.0.5+nobinonly-0ubuntu0.8.10.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"3.0.5+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.0.5","component":null,"pocket":"security"}]},{"name":"iceape","source":"https://ubuntu.com/security/cve?package=iceape","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=iceape","debian":"https://tracker.debian.org/pkg/iceape","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.1.14","component":null,"pocket":"security"}]},{"name":"mozilla-thunderbird","source":"https://ubuntu.com/security/cve?package=mozilla-thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mozilla-thunderbird","debian":"https://tracker.debian.org/pkg/mozilla-thunderbird","statuses":[{"release_codename":"dapper","status":"released","description":"1.5.0.13+1.5.0.15~prepatch080614i-0ubuntu0.6.06.1","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"seamonkey","source":"https://ubuntu.com/security/cve?package=seamonkey","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=seamonkey","debian":"https://tracker.debian.org/pkg/seamonkey","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.1.17+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.1.17+nobinonly-0ubuntu0.8.10.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"1.1.15+nobinonly-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"1.1.15+nobinonly-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.1.14","component":null,"pocket":"security"}]},{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"2.0.0.19+nobinonly-0ubuntu0.7.10.1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.0.0.19+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"2.0.0.19+nobinonly-0ubuntu0.8.10.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.0.0.19+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.0.0.19+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.0.0.19","component":null,"pocket":"security"}]},{"name":"xulrunner-1.9","source":"https://ubuntu.com/security/cve?package=xulrunner-1.9","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=xulrunner-1.9","debian":"https://tracker.debian.org/pkg/xulrunner-1.9","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.9.0.5+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.9.0.5+nobinonly-0ubuntu0.8.10.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.9.0.5+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.9.0.5","component":null,"pocket":"security"}]}],"notices_ids":["USN-690-3","USN-690-2","USN-701-1","USN-701-2"],"notices":[{"id":"USN-690-3","title":"Firefox vulnerabilities","summary":"Firefox vulnerabilities","instructions":"After a standard system upgrade you need to restart Firefox to effect the\nnecessary changes.\n","references":[],"published":"2008-12-18T00:17:53.636632","description":"Several flaws were discovered in the browser engine. These problems could allow\nan attacker to crash the browser and possibly execute arbitrary code with user\nprivileges. (CVE-2008-5500)\n\nBoris Zbarsky discovered that the same-origin check in Firefox could be\nbypassed by utilizing XBL-bindings. An attacker could exploit this to read data\nfrom other domains. (CVE-2008-5503)\n\nMarius Schilder discovered that Firefox did not properly handle redirects to\nan outside domain when an XMLHttpRequest was made to a same-origin resource.\nIt's possible that sensitive information could be revealed in the\nXMLHttpRequest response. (CVE-2008-5506)\n\nChris Evans discovered that Firefox did not properly protect a user's data when\naccessing a same-domain Javascript URL that is redirected to an unparsable\nJavascript off-site resource. If a user were tricked into opening a malicious\nwebsite, an attacker may be able to steal a limited amount of private data.\n(CVE-2008-5507)\n\nSeveral flaws were discovered in the Javascript engine. If a user were tricked\ninto opening a malicious website, an attacker could exploit this to execute\narbitrary Javascript code within the context of another website or with chrome\nprivileges. (CVE-2008-5511, CVE-2008-5512)\n","is_hidden":false,"release_packages":{"dapper":[{"name":"firefox","version":"1.5.dfsg+1.5.0.15~prepatch080614i-0ubuntu1","description":"","is_source":true},{"name":"firefox","version":"1.5.dfsg+1.5.0.15~prepatch080614i-0ubuntu1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/1.5.dfsg+1.5.0.15~prepatch080614i-0ubuntu1"}]},"type":"USN","cves_ids":["CVE-2008-5503","CVE-2008-5507","CVE-2008-5512","CVE-2008-5511","CVE-2008-5500","CVE-2008-5506"]},{"id":"USN-690-2","title":"Firefox vulnerabilities","summary":"Firefox vulnerabilities","instructions":"After a standard system upgrade you need to restart Firefox to effect the\nnecessary changes.\n","references":[],"published":"2008-12-18T00:08:10.708002","description":"Several flaws were discovered in the browser engine. These problems could allow\nan attacker to crash the browser and possibly execute arbitrary code with user\nprivileges. (CVE-2008-5500)\n\nBoris Zbarsky discovered that the same-origin check in Firefox could be\nbypassed by utilizing XBL-bindings. An attacker could exploit this to read data\nfrom other domains. (CVE-2008-5503)\n\nSeveral problems were discovered in the JavaScript engine. An attacker could\nexploit feed preview vulnerabilities to execute scripts from page content with\nchrome privileges. (CVE-2008-5504)\n\nMarius Schilder discovered that Firefox did not properly handle redirects to\nan outside domain when an XMLHttpRequest was made to a same-origin resource.\nIt's possible that sensitive information could be revealed in the\nXMLHttpRequest response. (CVE-2008-5506)\n\nChris Evans discovered that Firefox did not properly protect a user's data when\naccessing a same-domain Javascript URL that is redirected to an unparsable\nJavascript off-site resource. If a user were tricked into opening a malicious\nwebsite, an attacker may be able to steal a limited amount of private data.\n(CVE-2008-5507)\n\nChip Salzenberg, Justin Schuh, Tom Cross, and Peter William discovered Firefox\ndid not properly parse URLs when processing certain control characters.\n(CVE-2008-5508)\n\nKojima Hajime discovered that Firefox did not properly handle an escaped null\ncharacter. An attacker may be able to exploit this flaw to bypass script\nsanitization. (CVE-2008-5510)\n\nSeveral flaws were discovered in the Javascript engine. If a user were tricked\ninto opening a malicious website, an attacker could exploit this to execute\narbitrary Javascript code within the context of another website or with chrome\nprivileges. (CVE-2008-5511, CVE-2008-5512)\n\nFlaws were discovered in the session-restore feature of Firefox. If a user were\ntricked into opening a malicious website, an attacker could exploit this to\nperform cross-site scripting attacks or execute arbitrary Javascript code with\nchrome privileges. (CVE-2008-5513)\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"firefox","version":"2.0.0.19+nobinonly1-0ubuntu0.7.10.1","description":"","is_source":true},{"name":"firefox","version":"2.0.0.19+nobinonly1-0ubuntu0.7.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/2.0.0.19+nobinonly1-0ubuntu0.7.10.1"}]},"type":"USN","cves_ids":["CVE-2008-5510","CVE-2008-5504","CVE-2008-5508","CVE-2008-5513","CVE-2008-5500","CVE-2008-5503","CVE-2008-5506","CVE-2008-5507","CVE-2008-5511","CVE-2008-5512"]},{"id":"USN-701-1","title":"Thunderbird vulnerabilities","summary":"Thunderbird vulnerabilities","instructions":"After a standard system upgrade you need to restart Thunderbird to effect\nthe necessary changes.\n","references":[],"published":"2009-01-06T23:17:08.901828","description":"Several flaws were discovered in the browser engine. If a user had Javascript\nenabled, these problems could allow an attacker to crash Thunderbird and\npossibly execute arbitrary code with user privileges. (CVE-2008-5500)\n\nBoris Zbarsky discovered that the same-origin check in Thunderbird could be\nbypassed by utilizing XBL-bindings. If a user had Javascript enabled, an\nattacker could exploit this to read data from other domains. (CVE-2008-5503)\n\nMarius Schilder discovered that Thunderbird did not properly handle redirects\nto an outside domain when an XMLHttpRequest was made to a same-origin resource.\nWhen Javascript is enabled, it's possible that sensitive information could be\nrevealed in the XMLHttpRequest response. (CVE-2008-5506)\n\nChris Evans discovered that Thunderbird did not properly protect a user's data\nwhen accessing a same-domain Javascript URL that is redirected to an unparsable\nJavascript off-site resource. If a user were tricked into opening a malicious\nwebsite and had Javascript enabled, an attacker may be able to steal a limited\namount of private data. (CVE-2008-5507)\n\nChip Salzenberg, Justin Schuh, Tom Cross, and Peter William discovered\nThunderbird did not properly parse URLs when processing certain control\ncharacters. (CVE-2008-5508)\n\nKojima Hajime discovered that Thunderbird did not properly handle an escaped\nnull character. An attacker may be able to exploit this flaw to bypass script\nsanitization. (CVE-2008-5510)\n\nSeveral flaws were discovered in the Javascript engine. If a user were tricked\ninto opening a malicious website and had Javascript enabled, an attacker could\nexploit this to execute arbitrary Javascript code within the context of another\nwebsite or with chrome privileges. (CVE-2008-5511, CVE-2008-5512)\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"thunderbird","version":"2.0.0.19+nobinonly-0ubuntu0.7.10.1","description":"","is_source":true},{"name":"thunderbird","version":"2.0.0.19+nobinonly-0ubuntu0.7.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/2.0.0.19+nobinonly-0ubuntu0.7.10.1"}],"intrepid":[{"name":"thunderbird","version":"2.0.0.19+nobinonly-0ubuntu0.8.10.1","description":"","is_source":true},{"name":"thunderbird","version":"2.0.0.19+nobinonly-0ubuntu0.8.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/2.0.0.19+nobinonly-0ubuntu0.8.10.1"}],"hardy":[{"name":"thunderbird","version":"2.0.0.19+nobinonly-0ubuntu0.8.04.1","description":"","is_source":true},{"name":"thunderbird","version":"2.0.0.19+nobinonly-0ubuntu0.8.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/2.0.0.19+nobinonly-0ubuntu0.8.04.1"}]},"type":"USN","cves_ids":["CVE-2008-5500","CVE-2008-5503","CVE-2008-5506","CVE-2008-5507","CVE-2008-5508","CVE-2008-5510","CVE-2008-5511","CVE-2008-5512"]},{"id":"USN-701-2","title":"Thunderbird vulnerabilities","summary":"Thunderbird vulnerabilities","instructions":"After a standard system upgrade you need to restart Thunderbird to effect\nthe necessary changes.\n","references":[],"published":"2009-01-06T23:31:22.903118","description":"Several flaws were discovered in the browser engine. If a user had Javascript\nenabled, these problems could allow an attacker to crash Thunderbird and\npossibly execute arbitrary code with user privileges. (CVE-2008-5500)\n\nBoris Zbarsky discovered that the same-origin check in Thunderbird could be\nbypassed by utilizing XBL-bindings. If a user had Javascript enabled, an\nattacker could exploit this to read data from other domains. (CVE-2008-5503)\n\nMarius Schilder discovered that Thunderbird did not properly handle redirects\nto an outside domain when an XMLHttpRequest was made to a same-origin resource.\nWhen Javascript is enabled, it's possible that sensitive information could be\nrevealed in the XMLHttpRequest response. (CVE-2008-5506)\n\nChris Evans discovered that Thunderbird did not properly protect a user's data\nwhen accessing a same-domain Javascript URL that is redirected to an unparsable\nJavascript off-site resource. If a user were tricked into opening a malicious\nwebsite and had Javascript enabled, an attacker may be able to steal a limited\namount of private data. (CVE-2008-5507)\n\nChip Salzenberg, Justin Schuh, Tom Cross, and Peter William discovered\nThunderbird did not properly parse URLs when processing certain control\ncharacters. (CVE-2008-5508)\n\nSeveral flaws were discovered in the Javascript engine. If a user were tricked\ninto opening a malicious website and had Javascript enabled, an attacker could\nexploit this to execute arbitrary Javascript code within the context of another\nwebsite or with chrome privileges. (CVE-2008-5511, CVE-2008-5512)\n","is_hidden":false,"release_packages":{"dapper":[{"name":"mozilla-thunderbird","version":"1.5.0.13+1.5.0.15~prepatch080614i-0ubuntu0.6.06.1","description":"","is_source":true},{"name":"mozilla-thunderbird","version":"1.5.0.13+1.5.0.15~prepatch080614i-0ubuntu0.6.06.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/mozilla-thunderbird","version_link":"https://launchpad.net/ubuntu/+source/mozilla-thunderbird/1.5.0.13+1.5.0.15~prepatch080614i-0ubuntu0.6.06.1"}]},"type":"USN","cves_ids":["CVE-2008-5500","CVE-2008-5503","CVE-2008-5506","CVE-2008-5507","CVE-2008-5508","CVE-2008-5511","CVE-2008-5512"]}]},{"id":"CVE-2008-5502","published":"2008-12-17T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe layout engine in Mozilla Firefox 3.x before 3.0.5, Thunderbird 2.x\nbefore 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to\ncause a denial of service (crash) via vectors that trigger memory\ncorruption, related to the GetXMLEntity and FastAppendChar functions.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-690-1","https://www.cve.org/CVERecord?id=CVE-2008-5502"],"bugs":[""],"patches":{"firefox-3.0":[],"xulrunner-1.9":[],"seamonkey":[],"iceape":[],"thunderbird":[],"mozilla-thunderbird":[]},"tags":{},"packages":[{"name":"firefox-3.0","source":"https://ubuntu.com/security/cve?package=firefox-3.0","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=firefox-3.0","debian":"https://tracker.debian.org/pkg/firefox-3.0","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"3.0.5+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"3.0.5+nobinonly-0ubuntu0.8.10.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"3.0.5+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.0.5","component":null,"pocket":"security"}]},{"name":"iceape","source":"https://ubuntu.com/security/cve?package=iceape","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=iceape","debian":"https://tracker.debian.org/pkg/iceape","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.1.14","component":null,"pocket":"security"}]},{"name":"mozilla-thunderbird","source":"https://ubuntu.com/security/cve?package=mozilla-thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mozilla-thunderbird","debian":"https://tracker.debian.org/pkg/mozilla-thunderbird","statuses":[{"release_codename":"dapper","status":"released","description":"1.5.0.13+1.5.0.15~prepatch080614i-0ubuntu0.6.06.1","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"seamonkey","source":"https://ubuntu.com/security/cve?package=seamonkey","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=seamonkey","debian":"https://tracker.debian.org/pkg/seamonkey","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.1.17+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.1.17+nobinonly-0ubuntu0.8.10.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"1.1.15+nobinonly-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"1.1.15+nobinonly-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.1.14","component":null,"pocket":"security"}]},{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"2.0.0.19+nobinonly-0ubuntu0.7.10.1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.0.0.19+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"2.0.0.19+nobinonly-0ubuntu0.8.10.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.0.0.19+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.0.0.19+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.0.0.19","component":null,"pocket":"security"}]},{"name":"xulrunner-1.9","source":"https://ubuntu.com/security/cve?package=xulrunner-1.9","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=xulrunner-1.9","debian":"https://tracker.debian.org/pkg/xulrunner-1.9","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.9.0.5+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.9.0.5+nobinonly-0ubuntu0.8.10.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.9.0.5+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.9.0.5","component":null,"pocket":"security"}]}],"notices_ids":["USN-690-1"],"notices":[{"id":"USN-690-1","title":"Firefox and xulrunner vulnerabilities","summary":"Firefox and xulrunner vulnerabilities","instructions":"After a standard system upgrade you need to restart Firefox and any\napplications that use xulrunner, such as Epiphany, to effect the necessary\nchanges.\n","references":[],"published":"2008-12-17T23:50:57.166327","description":"Several flaws were discovered in the browser engine. These problems could allow\nan attacker to crash the browser and possibly execute arbitrary code with user\nprivileges. (CVE-2008-5500, CVE-2008-5501, CVE-2008-5502)\n\nIt was discovered that Firefox did not properly handle persistent cookie data.\nIf a user were tricked into opening a malicious website, an attacker could\nwrite persistent data in the user's browser and track the user across browsing\nsessions. (CVE-2008-5505)\n\nMarius Schilder discovered that Firefox did not properly handle redirects to\nan outside domain when an XMLHttpRequest was made to a same-origin resource.\nIt's possible that sensitive information could be revealed in the\nXMLHttpRequest response. (CVE-2008-5506)\n\nChris Evans discovered that Firefox did not properly protect a user's data when\naccessing a same-domain Javascript URL that is redirected to an unparsable\nJavascript off-site resource. If a user were tricked into opening a malicious\nwebsite, an attacker may be able to steal a limited amount of private data.\n(CVE-2008-5507)\n\nChip Salzenberg, Justin Schuh, Tom Cross, and Peter William discovered Firefox\ndid not properly parse URLs when processing certain control characters.\n(CVE-2008-5508)\n\nKojima Hajime discovered that Firefox did not properly handle an escaped null\ncharacter. An attacker may be able to exploit this flaw to bypass script\nsanitization. (CVE-2008-5510)\n\nSeveral flaws were discovered in the Javascript engine. If a user were tricked\ninto opening a malicious website, an attacker could exploit this to execute\narbitrary Javascript code within the context of another website or with chrome\nprivileges. (CVE-2008-5511, CVE-2008-5512)\n\nFlaws were discovered in the session-restore feature of Firefox. If a user were\ntricked into opening a malicious website, an attacker could exploit this to\nperform cross-site scripting attacks or execute arbitrary Javascript code with\nchrome privileges. (CVE-2008-5513)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"firefox-3.0","version":"3.0.5+nobinonly-0ubuntu0.8.04.1","description":"","is_source":true},{"name":"xulrunner-1.9","version":"1.9.0.5+nobinonly-0ubuntu0.8.04.1","description":"","is_source":true},{"name":"firefox-3.0","version":"3.0.5+nobinonly-0ubuntu0.8.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.0.5+nobinonly-0ubuntu0.8.04.1"},{"name":"xulrunner-1.9","version":"1.9.0.5+nobinonly-0ubuntu0.8.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9/1.9.0.5+nobinonly-0ubuntu0.8.04.1"}],"intrepid":[{"name":"firefox-3.0","version":"3.0.5+nobinonly-0ubuntu0.8.10.1","description":"","is_source":true},{"name":"xulrunner-1.9","version":"1.9.0.5+nobinonly-0ubuntu0.8.10.1","description":"","is_source":true},{"name":"firefox-3.0","version":"3.0.5+nobinonly-0ubuntu0.8.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.0.5+nobinonly-0ubuntu0.8.10.1"},{"name":"abrowser","version":"3.0.5+nobinonly-0ubuntu0.8.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.0.5+nobinonly-0ubuntu0.8.10.1"},{"name":"xulrunner-1.9","version":"1.9.0.5+nobinonly-0ubuntu0.8.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9/1.9.0.5+nobinonly-0ubuntu0.8.10.1"}]},"type":"USN","cves_ids":["CVE-2008-5502","CVE-2008-5501","CVE-2008-5505","CVE-2008-5500","CVE-2008-5506","CVE-2008-5507","CVE-2008-5508","CVE-2008-5510","CVE-2008-5511","CVE-2008-5512","CVE-2008-5513"]}]},{"id":"CVE-2008-5501","published":"2008-12-17T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe layout engine in Mozilla Firefox 3.x before 3.0.5, Thunderbird 2.x\nbefore 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to\ncause a denial of service via vectors that trigger an assertion failure.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-690-1","https://www.cve.org/CVERecord?id=CVE-2008-5501"],"bugs":[""],"patches":{"firefox-3.0":[],"xulrunner-1.9":[],"seamonkey":[],"iceape":[],"thunderbird":[],"mozilla-thunderbird":[]},"tags":{},"packages":[{"name":"firefox-3.0","source":"https://ubuntu.com/security/cve?package=firefox-3.0","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=firefox-3.0","debian":"https://tracker.debian.org/pkg/firefox-3.0","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"3.0.5+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"3.0.5+nobinonly-0ubuntu0.8.10.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"3.0.5+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.0.5","component":null,"pocket":"security"}]},{"name":"iceape","source":"https://ubuntu.com/security/cve?package=iceape","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=iceape","debian":"https://tracker.debian.org/pkg/iceape","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.1.14","component":null,"pocket":"security"}]},{"name":"mozilla-thunderbird","source":"https://ubuntu.com/security/cve?package=mozilla-thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mozilla-thunderbird","debian":"https://tracker.debian.org/pkg/mozilla-thunderbird","statuses":[{"release_codename":"dapper","status":"released","description":"1.5.0.13+1.5.0.15~prepatch080614i-0ubuntu0.6.06.1","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"seamonkey","source":"https://ubuntu.com/security/cve?package=seamonkey","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=seamonkey","debian":"https://tracker.debian.org/pkg/seamonkey","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.0.8+build1+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"1.1.15+nobinonly-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"1.1.15+nobinonly-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"1.1.15+nobinonly-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.1.14","component":null,"pocket":"security"}]},{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"2.0.0.19+nobinonly-0ubuntu0.7.10.1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.0.0.19+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"2.0.0.19+nobinonly-0ubuntu0.8.10.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.0.0.19+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.0.0.19+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.0.0.19+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.0.0.19","component":null,"pocket":"security"}]},{"name":"xulrunner-1.9","source":"https://ubuntu.com/security/cve?package=xulrunner-1.9","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=xulrunner-1.9","debian":"https://tracker.debian.org/pkg/xulrunner-1.9","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.9.0.5+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.9.0.5+nobinonly-0ubuntu0.8.10.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.9.0.5+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.9.0.5","component":null,"pocket":"security"}]}],"notices_ids":["USN-690-1"],"notices":[{"id":"USN-690-1","title":"Firefox and xulrunner vulnerabilities","summary":"Firefox and xulrunner vulnerabilities","instructions":"After a standard system upgrade you need to restart Firefox and any\napplications that use xulrunner, such as Epiphany, to effect the necessary\nchanges.\n","references":[],"published":"2008-12-17T23:50:57.166327","description":"Several flaws were discovered in the browser engine. These problems could allow\nan attacker to crash the browser and possibly execute arbitrary code with user\nprivileges. (CVE-2008-5500, CVE-2008-5501, CVE-2008-5502)\n\nIt was discovered that Firefox did not properly handle persistent cookie data.\nIf a user were tricked into opening a malicious website, an attacker could\nwrite persistent data in the user's browser and track the user across browsing\nsessions. (CVE-2008-5505)\n\nMarius Schilder discovered that Firefox did not properly handle redirects to\nan outside domain when an XMLHttpRequest was made to a same-origin resource.\nIt's possible that sensitive information could be revealed in the\nXMLHttpRequest response. (CVE-2008-5506)\n\nChris Evans discovered that Firefox did not properly protect a user's data when\naccessing a same-domain Javascript URL that is redirected to an unparsable\nJavascript off-site resource. If a user were tricked into opening a malicious\nwebsite, an attacker may be able to steal a limited amount of private data.\n(CVE-2008-5507)\n\nChip Salzenberg, Justin Schuh, Tom Cross, and Peter William discovered Firefox\ndid not properly parse URLs when processing certain control characters.\n(CVE-2008-5508)\n\nKojima Hajime discovered that Firefox did not properly handle an escaped null\ncharacter. An attacker may be able to exploit this flaw to bypass script\nsanitization. (CVE-2008-5510)\n\nSeveral flaws were discovered in the Javascript engine. If a user were tricked\ninto opening a malicious website, an attacker could exploit this to execute\narbitrary Javascript code within the context of another website or with chrome\nprivileges. (CVE-2008-5511, CVE-2008-5512)\n\nFlaws were discovered in the session-restore feature of Firefox. If a user were\ntricked into opening a malicious website, an attacker could exploit this to\nperform cross-site scripting attacks or execute arbitrary Javascript code with\nchrome privileges. (CVE-2008-5513)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"firefox-3.0","version":"3.0.5+nobinonly-0ubuntu0.8.04.1","description":"","is_source":true},{"name":"xulrunner-1.9","version":"1.9.0.5+nobinonly-0ubuntu0.8.04.1","description":"","is_source":true},{"name":"firefox-3.0","version":"3.0.5+nobinonly-0ubuntu0.8.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.0.5+nobinonly-0ubuntu0.8.04.1"},{"name":"xulrunner-1.9","version":"1.9.0.5+nobinonly-0ubuntu0.8.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9/1.9.0.5+nobinonly-0ubuntu0.8.04.1"}],"intrepid":[{"name":"firefox-3.0","version":"3.0.5+nobinonly-0ubuntu0.8.10.1","description":"","is_source":true},{"name":"xulrunner-1.9","version":"1.9.0.5+nobinonly-0ubuntu0.8.10.1","description":"","is_source":true},{"name":"firefox-3.0","version":"3.0.5+nobinonly-0ubuntu0.8.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.0.5+nobinonly-0ubuntu0.8.10.1"},{"name":"abrowser","version":"3.0.5+nobinonly-0ubuntu0.8.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.0.5+nobinonly-0ubuntu0.8.10.1"},{"name":"xulrunner-1.9","version":"1.9.0.5+nobinonly-0ubuntu0.8.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9/1.9.0.5+nobinonly-0ubuntu0.8.10.1"}]},"type":"USN","cves_ids":["CVE-2008-5502","CVE-2008-5501","CVE-2008-5505","CVE-2008-5500","CVE-2008-5506","CVE-2008-5507","CVE-2008-5508","CVE-2008-5510","CVE-2008-5511","CVE-2008-5512","CVE-2008-5513"]}]},{"id":"CVE-2008-5500","published":"2008-12-17T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe layout engine in Mozilla Firefox 3.x before 3.0.5 and 2.x before\n2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14\nallows remote attackers to cause a denial of service (crash) and possibly\ntrigger memory corruption via vectors related to (1) a reachable assertion\nor (2) an integer overflow.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-690-3","https://ubuntu.com/security/notices/USN-690-2","https://ubuntu.com/security/notices/USN-690-1","https://ubuntu.com/security/notices/USN-701-1","https://ubuntu.com/security/notices/USN-701-2","https://www.cve.org/CVERecord?id=CVE-2008-5500"],"bugs":[""],"patches":{"firefox":[],"firefox-3.0":[],"xulrunner":[],"xulrunner-1.9":[],"seamonkey":[],"iceape":[],"thunderbird":[],"mozilla-thunderbird":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"dapper","status":"released","description":"1.5.dfsg+1.5.0.15~prepatch080614i-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"2.0.0.19+nobinonly1-0ubuntu0.7.10.1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.0.0.19+nobinonly1-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"3.0.5+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"3.0.5+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"3.0.5+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.0.0.19","component":null,"pocket":"security"}]},{"name":"firefox-3.0","source":"https://ubuntu.com/security/cve?package=firefox-3.0","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=firefox-3.0","debian":"https://tracker.debian.org/pkg/firefox-3.0","statuses":[{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"3.0.5+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"3.0.5+nobinonly-0ubuntu0.8.10.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"3.0.5+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.0.5","component":null,"pocket":"security"}]},{"name":"iceape","source":"https://ubuntu.com/security/cve?package=iceape","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=iceape","debian":"https://tracker.debian.org/pkg/iceape","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.1.14","component":null,"pocket":"security"}]},{"name":"mozilla-thunderbird","source":"https://ubuntu.com/security/cve?package=mozilla-thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mozilla-thunderbird","debian":"https://tracker.debian.org/pkg/mozilla-thunderbird","statuses":[{"release_codename":"dapper","status":"released","description":"1.5.0.13+1.5.0.15~prepatch080614i-0ubuntu0.6.06.1","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"seamonkey","source":"https://ubuntu.com/security/cve?package=seamonkey","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=seamonkey","debian":"https://tracker.debian.org/pkg/seamonkey","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.1.15+nobinonly-0ubuntu0.8.04.2","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.1.15+nobinonly-0ubuntu0.8.10.2","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.1.15+nobinonly-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1.1.15+nobinonly-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"1.1.15+nobinonly-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"1.1.15+nobinonly-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"1.1.15+nobinonly-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.1.14","component":null,"pocket":"security"}]},{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"2.0.0.19+nobinonly-0ubuntu0.7.10.1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.0.0.19+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"2.0.0.19+nobinonly-0ubuntu0.8.10.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.0.0.19+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.0.0.19+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.0.0.19+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"2.0.0.19+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"2.0.0.19+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.0.0.19","component":null,"pocket":"security"}]},{"name":"xulrunner","source":"https://ubuntu.com/security/cve?package=xulrunner","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=xulrunner","debian":"https://tracker.debian.org/pkg/xulrunner","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"1.8.1.18+nobinonly.b308.cvs20090331t155113-0ubuntu0.7.10.1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.8.1.18+nobinonly.b308.cvs20090331t155113-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.8.1.18+nobinonly.b308.cvs20090331t155113-0ubuntu0.8.10.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"xulrunner-1.9","source":"https://ubuntu.com/security/cve?package=xulrunner-1.9","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=xulrunner-1.9","debian":"https://tracker.debian.org/pkg/xulrunner-1.9","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.9.0.5+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.9.0.5+nobinonly-0ubuntu0.8.10.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.9.0.5+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-690-1","USN-690-3","USN-690-2","USN-701-1","USN-701-2"],"notices":[{"id":"USN-690-1","title":"Firefox and xulrunner vulnerabilities","summary":"Firefox and xulrunner vulnerabilities","instructions":"After a standard system upgrade you need to restart Firefox and any\napplications that use xulrunner, such as Epiphany, to effect the necessary\nchanges.\n","references":[],"published":"2008-12-17T23:50:57.166327","description":"Several flaws were discovered in the browser engine. These problems could allow\nan attacker to crash the browser and possibly execute arbitrary code with user\nprivileges. (CVE-2008-5500, CVE-2008-5501, CVE-2008-5502)\n\nIt was discovered that Firefox did not properly handle persistent cookie data.\nIf a user were tricked into opening a malicious website, an attacker could\nwrite persistent data in the user's browser and track the user across browsing\nsessions. (CVE-2008-5505)\n\nMarius Schilder discovered that Firefox did not properly handle redirects to\nan outside domain when an XMLHttpRequest was made to a same-origin resource.\nIt's possible that sensitive information could be revealed in the\nXMLHttpRequest response. (CVE-2008-5506)\n\nChris Evans discovered that Firefox did not properly protect a user's data when\naccessing a same-domain Javascript URL that is redirected to an unparsable\nJavascript off-site resource. If a user were tricked into opening a malicious\nwebsite, an attacker may be able to steal a limited amount of private data.\n(CVE-2008-5507)\n\nChip Salzenberg, Justin Schuh, Tom Cross, and Peter William discovered Firefox\ndid not properly parse URLs when processing certain control characters.\n(CVE-2008-5508)\n\nKojima Hajime discovered that Firefox did not properly handle an escaped null\ncharacter. An attacker may be able to exploit this flaw to bypass script\nsanitization. (CVE-2008-5510)\n\nSeveral flaws were discovered in the Javascript engine. If a user were tricked\ninto opening a malicious website, an attacker could exploit this to execute\narbitrary Javascript code within the context of another website or with chrome\nprivileges. (CVE-2008-5511, CVE-2008-5512)\n\nFlaws were discovered in the session-restore feature of Firefox. If a user were\ntricked into opening a malicious website, an attacker could exploit this to\nperform cross-site scripting attacks or execute arbitrary Javascript code with\nchrome privileges. (CVE-2008-5513)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"firefox-3.0","version":"3.0.5+nobinonly-0ubuntu0.8.04.1","description":"","is_source":true},{"name":"xulrunner-1.9","version":"1.9.0.5+nobinonly-0ubuntu0.8.04.1","description":"","is_source":true},{"name":"firefox-3.0","version":"3.0.5+nobinonly-0ubuntu0.8.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.0.5+nobinonly-0ubuntu0.8.04.1"},{"name":"xulrunner-1.9","version":"1.9.0.5+nobinonly-0ubuntu0.8.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9/1.9.0.5+nobinonly-0ubuntu0.8.04.1"}],"intrepid":[{"name":"firefox-3.0","version":"3.0.5+nobinonly-0ubuntu0.8.10.1","description":"","is_source":true},{"name":"xulrunner-1.9","version":"1.9.0.5+nobinonly-0ubuntu0.8.10.1","description":"","is_source":true},{"name":"firefox-3.0","version":"3.0.5+nobinonly-0ubuntu0.8.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.0.5+nobinonly-0ubuntu0.8.10.1"},{"name":"abrowser","version":"3.0.5+nobinonly-0ubuntu0.8.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.0.5+nobinonly-0ubuntu0.8.10.1"},{"name":"xulrunner-1.9","version":"1.9.0.5+nobinonly-0ubuntu0.8.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9/1.9.0.5+nobinonly-0ubuntu0.8.10.1"}]},"type":"USN","cves_ids":["CVE-2008-5502","CVE-2008-5501","CVE-2008-5505","CVE-2008-5500","CVE-2008-5506","CVE-2008-5507","CVE-2008-5508","CVE-2008-5510","CVE-2008-5511","CVE-2008-5512","CVE-2008-5513"]},{"id":"USN-690-3","title":"Firefox vulnerabilities","summary":"Firefox vulnerabilities","instructions":"After a standard system upgrade you need to restart Firefox to effect the\nnecessary changes.\n","references":[],"published":"2008-12-18T00:17:53.636632","description":"Several flaws were discovered in the browser engine. These problems could allow\nan attacker to crash the browser and possibly execute arbitrary code with user\nprivileges. (CVE-2008-5500)\n\nBoris Zbarsky discovered that the same-origin check in Firefox could be\nbypassed by utilizing XBL-bindings. An attacker could exploit this to read data\nfrom other domains. (CVE-2008-5503)\n\nMarius Schilder discovered that Firefox did not properly handle redirects to\nan outside domain when an XMLHttpRequest was made to a same-origin resource.\nIt's possible that sensitive information could be revealed in the\nXMLHttpRequest response. (CVE-2008-5506)\n\nChris Evans discovered that Firefox did not properly protect a user's data when\naccessing a same-domain Javascript URL that is redirected to an unparsable\nJavascript off-site resource. If a user were tricked into opening a malicious\nwebsite, an attacker may be able to steal a limited amount of private data.\n(CVE-2008-5507)\n\nSeveral flaws were discovered in the Javascript engine. If a user were tricked\ninto opening a malicious website, an attacker could exploit this to execute\narbitrary Javascript code within the context of another website or with chrome\nprivileges. (CVE-2008-5511, CVE-2008-5512)\n","is_hidden":false,"release_packages":{"dapper":[{"name":"firefox","version":"1.5.dfsg+1.5.0.15~prepatch080614i-0ubuntu1","description":"","is_source":true},{"name":"firefox","version":"1.5.dfsg+1.5.0.15~prepatch080614i-0ubuntu1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/1.5.dfsg+1.5.0.15~prepatch080614i-0ubuntu1"}]},"type":"USN","cves_ids":["CVE-2008-5503","CVE-2008-5507","CVE-2008-5512","CVE-2008-5511","CVE-2008-5500","CVE-2008-5506"]},{"id":"USN-690-2","title":"Firefox vulnerabilities","summary":"Firefox vulnerabilities","instructions":"After a standard system upgrade you need to restart Firefox to effect the\nnecessary changes.\n","references":[],"published":"2008-12-18T00:08:10.708002","description":"Several flaws were discovered in the browser engine. These problems could allow\nan attacker to crash the browser and possibly execute arbitrary code with user\nprivileges. (CVE-2008-5500)\n\nBoris Zbarsky discovered that the same-origin check in Firefox could be\nbypassed by utilizing XBL-bindings. An attacker could exploit this to read data\nfrom other domains. (CVE-2008-5503)\n\nSeveral problems were discovered in the JavaScript engine. An attacker could\nexploit feed preview vulnerabilities to execute scripts from page content with\nchrome privileges. (CVE-2008-5504)\n\nMarius Schilder discovered that Firefox did not properly handle redirects to\nan outside domain when an XMLHttpRequest was made to a same-origin resource.\nIt's possible that sensitive information could be revealed in the\nXMLHttpRequest response. (CVE-2008-5506)\n\nChris Evans discovered that Firefox did not properly protect a user's data when\naccessing a same-domain Javascript URL that is redirected to an unparsable\nJavascript off-site resource. If a user were tricked into opening a malicious\nwebsite, an attacker may be able to steal a limited amount of private data.\n(CVE-2008-5507)\n\nChip Salzenberg, Justin Schuh, Tom Cross, and Peter William discovered Firefox\ndid not properly parse URLs when processing certain control characters.\n(CVE-2008-5508)\n\nKojima Hajime discovered that Firefox did not properly handle an escaped null\ncharacter. An attacker may be able to exploit this flaw to bypass script\nsanitization. (CVE-2008-5510)\n\nSeveral flaws were discovered in the Javascript engine. If a user were tricked\ninto opening a malicious website, an attacker could exploit this to execute\narbitrary Javascript code within the context of another website or with chrome\nprivileges. (CVE-2008-5511, CVE-2008-5512)\n\nFlaws were discovered in the session-restore feature of Firefox. If a user were\ntricked into opening a malicious website, an attacker could exploit this to\nperform cross-site scripting attacks or execute arbitrary Javascript code with\nchrome privileges. (CVE-2008-5513)\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"firefox","version":"2.0.0.19+nobinonly1-0ubuntu0.7.10.1","description":"","is_source":true},{"name":"firefox","version":"2.0.0.19+nobinonly1-0ubuntu0.7.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/2.0.0.19+nobinonly1-0ubuntu0.7.10.1"}]},"type":"USN","cves_ids":["CVE-2008-5510","CVE-2008-5504","CVE-2008-5508","CVE-2008-5513","CVE-2008-5500","CVE-2008-5503","CVE-2008-5506","CVE-2008-5507","CVE-2008-5511","CVE-2008-5512"]},{"id":"USN-701-1","title":"Thunderbird vulnerabilities","summary":"Thunderbird vulnerabilities","instructions":"After a standard system upgrade you need to restart Thunderbird to effect\nthe necessary changes.\n","references":[],"published":"2009-01-06T23:17:08.901828","description":"Several flaws were discovered in the browser engine. If a user had Javascript\nenabled, these problems could allow an attacker to crash Thunderbird and\npossibly execute arbitrary code with user privileges. (CVE-2008-5500)\n\nBoris Zbarsky discovered that the same-origin check in Thunderbird could be\nbypassed by utilizing XBL-bindings. If a user had Javascript enabled, an\nattacker could exploit this to read data from other domains. (CVE-2008-5503)\n\nMarius Schilder discovered that Thunderbird did not properly handle redirects\nto an outside domain when an XMLHttpRequest was made to a same-origin resource.\nWhen Javascript is enabled, it's possible that sensitive information could be\nrevealed in the XMLHttpRequest response. (CVE-2008-5506)\n\nChris Evans discovered that Thunderbird did not properly protect a user's data\nwhen accessing a same-domain Javascript URL that is redirected to an unparsable\nJavascript off-site resource. If a user were tricked into opening a malicious\nwebsite and had Javascript enabled, an attacker may be able to steal a limited\namount of private data. (CVE-2008-5507)\n\nChip Salzenberg, Justin Schuh, Tom Cross, and Peter William discovered\nThunderbird did not properly parse URLs when processing certain control\ncharacters. (CVE-2008-5508)\n\nKojima Hajime discovered that Thunderbird did not properly handle an escaped\nnull character. An attacker may be able to exploit this flaw to bypass script\nsanitization. (CVE-2008-5510)\n\nSeveral flaws were discovered in the Javascript engine. If a user were tricked\ninto opening a malicious website and had Javascript enabled, an attacker could\nexploit this to execute arbitrary Javascript code within the context of another\nwebsite or with chrome privileges. (CVE-2008-5511, CVE-2008-5512)\n","is_hidden":false,"release_packages":{"gutsy":[{"name":"thunderbird","version":"2.0.0.19+nobinonly-0ubuntu0.7.10.1","description":"","is_source":true},{"name":"thunderbird","version":"2.0.0.19+nobinonly-0ubuntu0.7.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/2.0.0.19+nobinonly-0ubuntu0.7.10.1"}],"intrepid":[{"name":"thunderbird","version":"2.0.0.19+nobinonly-0ubuntu0.8.10.1","description":"","is_source":true},{"name":"thunderbird","version":"2.0.0.19+nobinonly-0ubuntu0.8.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/2.0.0.19+nobinonly-0ubuntu0.8.10.1"}],"hardy":[{"name":"thunderbird","version":"2.0.0.19+nobinonly-0ubuntu0.8.04.1","description":"","is_source":true},{"name":"thunderbird","version":"2.0.0.19+nobinonly-0ubuntu0.8.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/2.0.0.19+nobinonly-0ubuntu0.8.04.1"}]},"type":"USN","cves_ids":["CVE-2008-5500","CVE-2008-5503","CVE-2008-5506","CVE-2008-5507","CVE-2008-5508","CVE-2008-5510","CVE-2008-5511","CVE-2008-5512"]},{"id":"USN-701-2","title":"Thunderbird vulnerabilities","summary":"Thunderbird vulnerabilities","instructions":"After a standard system upgrade you need to restart Thunderbird to effect\nthe necessary changes.\n","references":[],"published":"2009-01-06T23:31:22.903118","description":"Several flaws were discovered in the browser engine. If a user had Javascript\nenabled, these problems could allow an attacker to crash Thunderbird and\npossibly execute arbitrary code with user privileges. (CVE-2008-5500)\n\nBoris Zbarsky discovered that the same-origin check in Thunderbird could be\nbypassed by utilizing XBL-bindings. If a user had Javascript enabled, an\nattacker could exploit this to read data from other domains. (CVE-2008-5503)\n\nMarius Schilder discovered that Thunderbird did not properly handle redirects\nto an outside domain when an XMLHttpRequest was made to a same-origin resource.\nWhen Javascript is enabled, it's possible that sensitive information could be\nrevealed in the XMLHttpRequest response. (CVE-2008-5506)\n\nChris Evans discovered that Thunderbird did not properly protect a user's data\nwhen accessing a same-domain Javascript URL that is redirected to an unparsable\nJavascript off-site resource. If a user were tricked into opening a malicious\nwebsite and had Javascript enabled, an attacker may be able to steal a limited\namount of private data. (CVE-2008-5507)\n\nChip Salzenberg, Justin Schuh, Tom Cross, and Peter William discovered\nThunderbird did not properly parse URLs when processing certain control\ncharacters. (CVE-2008-5508)\n\nSeveral flaws were discovered in the Javascript engine. If a user were tricked\ninto opening a malicious website and had Javascript enabled, an attacker could\nexploit this to execute arbitrary Javascript code within the context of another\nwebsite or with chrome privileges. (CVE-2008-5511, CVE-2008-5512)\n","is_hidden":false,"release_packages":{"dapper":[{"name":"mozilla-thunderbird","version":"1.5.0.13+1.5.0.15~prepatch080614i-0ubuntu0.6.06.1","description":"","is_source":true},{"name":"mozilla-thunderbird","version":"1.5.0.13+1.5.0.15~prepatch080614i-0ubuntu0.6.06.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/mozilla-thunderbird","version_link":"https://launchpad.net/ubuntu/+source/mozilla-thunderbird/1.5.0.13+1.5.0.15~prepatch080614i-0ubuntu0.6.06.1"}]},"type":"USN","cves_ids":["CVE-2008-5500","CVE-2008-5503","CVE-2008-5506","CVE-2008-5507","CVE-2008-5508","CVE-2008-5511","CVE-2008-5512"]}]},{"id":"CVE-2008-5587","published":"2008-12-16T19:07:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nDirectory traversal vulnerability in libraries/lib.inc.php in phpPgAdmin\n4.2.1 and earlier, when register_globals is enabled, allows remote\nattackers to read arbitrary files via a .. (dot dot) in the _language\nparameter to index.php.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508026","https://www.cve.org/CVERecord?id=CVE-2008-5587"],"bugs":[""],"patches":{"phppgadmin":[]},"tags":{},"packages":[{"name":"phppgadmin","source":"https://ubuntu.com/security/cve?package=phppgadmin","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=phppgadmin","debian":"https://tracker.debian.org/pkg/phppgadmin","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"4.2.1-1.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"4.2.1-1.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"4.2.1-1.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"4.2.1-1.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"4.2.1-1.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"4.2.1-1.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.2.1-1.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-5430","published":"2008-12-13T08:40:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMozilla Thunderbird 2.0.14 does not properly handle (1) multipart/mixed\ne-mail messages with many MIME parts and possibly (2) e-mail messages with\nmany \"Content-type: message/rfc822;\" headers, which might allow remote\nattackers to cause a denial of service (stack consumption or other resource\nconsumption) via a large e-mail message, a related issue to CVE-2006-1173.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"DoS, no security impact"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-5430"],"bugs":[""],"patches":{"thunderbird":[]},"tags":{},"packages":[{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-5525","published":"2008-12-12T18:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nClamAV 0.94.1 and possibly 0.93.1, when Internet Explorer 6 or 7 is used,\nallows remote attackers to bypass detection of malware in an HTML document\nby placing an MZ header (aka \"EXE info\") at the beginning, and modifying\nthe filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg\nextension, as demonstrated by a document containing a CVE-2006-5745\nexploit.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"not a security issue in clamav"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-5525"],"bugs":[""],"patches":{"clamav":[]},"tags":{},"packages":[{"name":"clamav","source":"https://ubuntu.com/security/cve?package=clamav","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=clamav","debian":"https://tracker.debian.org/pkg/clamav","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-5432","published":"2008-12-11T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site scripting (XSS) vulnerability in Moodle before 1.6.8, 1.7 before\n1.7.6, 1.8 before 1.8.7, and 1.9 before 1.9.3 allows remote attackers to\ninject arbitrary web script or HTML via a Wiki page name (aka page title).","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508593","https://ubuntu.com/security/notices/USN-791-1","https://www.cve.org/CVERecord?id=CVE-2008-5432"],"bugs":[""],"patches":{"moodle":[]},"tags":{},"packages":[{"name":"moodle","source":"https://ubuntu.com/security/cve?package=moodle","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=moodle","debian":"https://tracker.debian.org/pkg/moodle","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.8.2-1ubuntu4.2","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.8.2-1.2ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"1.9.4.dfsg-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"1.9.4.dfsg-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.8.2.dfsg-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-791-1"],"notices":[{"id":"USN-791-1","title":"Moodle vulnerabilities","summary":"Moodle vulnerabilities","instructions":"After a standard system upgrade you need to access the Moodle instance\nand accept the database update to clear any invalid cached data.\n","references":[],"published":"2009-06-24T20:00:13.114186","description":"Thor Larholm discovered that PHPMailer, as used by Moodle, did not\ncorrectly escape email addresses.  A local attacker with direct access\nto the Moodle database could exploit this to execute arbitrary commands\nas the web server user. (CVE-2007-3215)\n\nNigel McNie discovered that fetching https URLs did not correctly escape\nshell meta-characters.  An authenticated remote attacker could execute\narbitrary commands as the web server user, if curl was installed and\nconfigured. (CVE-2008-4796, MSA-09-0003)\n\nIt was discovered that Smarty (also included in Moodle), did not\ncorrectly filter certain inputs.  An authenticated remote attacker could\nexploit this to execute arbitrary PHP commands as the web server user.\n(CVE-2008-4810, CVE-2008-4811, CVE-2009-1669)\n\nIt was discovered that the unused SpellChecker extension in Moodle did not\ncorrectly handle temporary files.  If the tool had been locally modified,\nit could be made to overwrite arbitrary local files via symlinks.\n(CVE-2008-5153)\n\nMike Churchward discovered that Moodle did not correctly filter Wiki page\ntitles in certain areas.  An authenticated remote attacker could exploit\nthis to cause cross-site scripting (XSS), which could be used to modify\nor steal confidential data of other users within the same web domain.\n(CVE-2008-5432, MSA-08-0022)\n\nIt was discovered that the HTML sanitizer, \"Login as\" feature, and logging\nin Moodle did not correctly handle certain inputs.  An authenticated\nremote attacker could exploit this to generate XSS, which could be used\nto modify or steal confidential data of other users within the same\nweb domain.  (CVE-2008-5619, CVE-2009-0500, CVE-2009-0502, MSA-08-0026,\nMSA-09-0004, MSA-09-0007)\n\nIt was discovered that the HotPot module in Moodle did not correctly\nfilter SQL inputs.  An authenticated remote attacker could execute\narbitrary SQL commands as the moodle database user, leading to a loss\nof privacy or denial of service.  (CVE-2008-6124, MSA-08-0010)\n\nKevin Madura discovered that the forum actions and messaging settings\nin Moodle were not protected from cross-site request forgery (CSRF).\nIf an authenticated user were tricked into visiting a malicious\nwebsite while logged into Moodle, a remote attacker could change the\nuser's configurations or forum content.  (CVE-2009-0499, MSA-09-0008,\nMSA-08-0023)\n\nDaniel Cabezas discovered that Moodle would leak usernames from the\nCalendar Export tool.  A remote attacker could gather a list of users,\nleading to a loss of privacy.  (CVE-2009-0501, MSA-09-0006)\n\nChristian Eibl discovered that the TeX filter in Moodle allowed any\nfunction to be used.  An authenticated remote attacker could post\na specially crafted TeX formula to execute arbitrary TeX functions,\npotentially reading any file accessible to the web server user, leading\nto a loss of privacy.  (CVE-2009-1171, MSA-09-0009)\n\nJohannes Kuhn discovered that Moodle did not correctly validate user\npermissions when attempting to switch user accounts.  An authenticated\nremote attacker could switch to any other Moodle user, leading to a loss\nof privacy.  (MSA-08-0003)\n\nHanno Boeck discovered that unconfigured Moodle instances contained\nXSS vulnerabilities.  An unauthenticated remote attacker could exploit\nthis to modify or steal confidential data of other users within the same\nweb domain.  (MSA-08-0004)\n\nDebbie McDonald, Mauno Korpelainen, Howard Miller, and Juan Segarra\nMontesinos discovered that when users were deleted from Moodle, their\nprofiles and avatars were still visible.  An authenticated remote attacker\ncould exploit this to store information in profiles even after they were\nremoved, leading to spam traffic.  (MSA-08-0015, MSA-09-0001, MSA-09-0002)\n\nLars Vogdt discovered that Moodle did not correctly filter certain inputs.\nAn authenticated remote attacker could exploit this to generate XSS from\nwhich they could modify or steal confidential data of other users within\nthe same web domain.  (MSA-08-0021)\n\nIt was discovered that Moodle did not correctly filter inputs for group\ncreation, mnet, essay question, HOST param, wiki param, and others.\nAn authenticated remote attacker could exploit this to generate XSS\nfrom which they could modify or steal confidential data of other users\nwithin the same web domain.  (MDL-9288, MDL-11759, MDL-12079, MDL-12793,\nMDL-14806)\n\nIt was discovered that Moodle did not correctly filter SQL inputs when\nperforming a restore.  An attacker authenticated as a Moodle administrator\ncould execute arbitrary SQL commands as the moodle database user,\nleading to a loss of privacy or denial of service. (MDL-11857)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"moodle","version":"1.8.2-1ubuntu4.2","description":"","is_source":true},{"name":"moodle","version":"1.8.2-1ubuntu4.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/moodle","version_link":"https://launchpad.net/ubuntu/+source/moodle/1.8.2-1ubuntu4.2"}],"intrepid":[{"name":"moodle","version":"1.8.2-1.2ubuntu2.1","description":"","is_source":true},{"name":"moodle","version":"1.8.2-1.2ubuntu2.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/moodle","version_link":"https://launchpad.net/ubuntu/+source/moodle/1.8.2-1.2ubuntu2.1"}]},"type":"USN","cves_ids":["CVE-2009-0500","CVE-2007-3215","CVE-2008-5619","CVE-2009-0502","CVE-2008-5432","CVE-2008-5153","CVE-2009-0499","CVE-2008-4810","CVE-2009-0501","CVE-2008-6124","CVE-2008-4796","CVE-2008-4811","CVE-2009-1171","CVE-2009-1669"]}]}],"offset":74600,"limit":20,"total_results":79316}