Vulnerability Database

290,020

Total vulnerabilities in the database

CVE-2008-0415

Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8 allows remote attackers to execute script outside of the sandbox and conduct cross-site scripting (XSS) attacks via multiple vectors including the XMLDocument.load function, aka "JavaScript privilege escalation bugs."

  • Published: Feb 8, 2008
  • Updated: Apr 13, 2023
  • CVE: CVE-2008-0415
  • Severity: Low
  • Exploit:

CVSS v2:

  • Severity: Low
  • Score: 4.3
  • AV:N/AC:M/Au:N/C:N/I:P/A:N
Software From Fixed in
mozilla / thunderbird - 2.0.0.11.x
mozilla / seamonkey - 1.1.7.x
mozilla / firefox - 2.0.0.11.x