Return to CVE list

CVE-2008-1240

5.0
Medium

CVE-2008-1240

secalert@redhat.com
Modified

Description

LiveConnect in Mozilla Firefox before 2.0.0.13 and SeaMonkey before 1.1.9 does not properly parse the content origin for jar: URIs before sending them to the Java plugin, which allows remote attackers to access arbitrary ports on the local machine. NOTE: this is closely related to CVE-2008-1195.

Exploits

No known exploits found for this CVE.

Search Exploit-DB

References

af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/29526
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/29539
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/29541
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/29547
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/29558
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/29560
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/29616
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/29645
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/30327
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/30620
af854a3a-2127-422b-91ae-364da2661108
http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0128
af854a3a-2127-422b-91ae-364da2661108
http://www.debian.org/security/2008/dsa-1532
af854a3a-2127-422b-91ae-364da2661108
http://www.debian.org/security/2008/dsa-1534
af854a3a-2127-422b-91ae-364da2661108
http://www.debian.org/security/2008/dsa-1535
af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/bid/28448
af854a3a-2127-422b-91ae-364da2661108
http://www.ubuntu.com/usn/usn-592-1
af854a3a-2127-422b-91ae-364da2661108
http://www.us-cert.gov/cas/techalerts/TA08-087A.html