CVE-2008-1240
Last modified
CVE-2008-1240 is a vulnerability of currently unknown severity. LiveConnect in Mozilla Firefox before 2.0.0.13 and SeaMonkey before 1.1.9 does not properly parse the content origin for jar: URIs before sending them to the Java plugin, which allows remote attackers to access arbitrary ports on the local machine. NOTE: this is closely related to CVE-2008-1195.. EPSS estimates a 3.22% chance of exploitation in the next 30 days.
Description
LiveConnect in Mozilla Firefox before 2.0.0.13 and SeaMonkey before 1.1.9 does not properly parse the content origin for jar: URIs before sending them to the Java plugin, which allows remote attackers to access arbitrary ports on the local machine. NOTE: this is closely related to CVE-2008-1195.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox | <= 2.0.0.12 |
| Mozilla | Seamonkey | <= 1.1.8 |
References
- http://www.us-cert.gov/cas/techalerts/TA08-087A.htmlUS Government Resource
- http://www.us-cert.gov/cas/techalerts/TA08-087A.htmlUS Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-1240?
How severe is CVE-2008-1240?
How do I fix CVE-2008-1240?
Are you affected by CVE-2008-1240?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
