Bugsalert.com
Security News about Viruses, Spyware,
Trojans, Malware, XSS attacks.

CVE-2008-1240 (Firefox, SeaMonkey)

BugsAlert Home > CVE-2008-1240 (Firefox, SeaMonkey)
 
 

LiveConnect in Mozilla Firefox before 2.0.0.13 and SeaMonkey before 1.1.9 does not properly parse the content origin for jar: URIs before sending them to the Java plugin, which allows remote attackers to access arbitrary ports on the local machine. NOTE: this is closely related to CVE-2008-1195.




Original Source: http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-1240

Learn more about CVE-2008-1240 (Firefox, SeaMonkey)
 
Tags: cve-2008-1240 firefox seamonkey

Related Items

      FrSIRT - Mandriva Security Update Fixes Blender Buffer Overflow Vulnerability

      CVE-2007-6164 (Eurologon CMS)

      CVE-2008-2728 (Ruby)

      PeerCast "HTTP::getAuthUserPass()" Buffer Overflow Vulnerability

      CVE-2008-1074 (GROUP_E)

      FrSIRT - Turbolinux Security Update Fixes Httpd Multiple Remote Vulnerabilities

      FrSIRT - rPath Linux Security Update Fixes PHP Code Execution Vulnerabilities

 

Pixel