CVE-2008-2933
17.07.2008, 13:41
Mozilla Firefox before 2.0.0.16, and 3.x before 3.0.1, interprets '|' (pipe) characters in a command-line URI as requests to open multiple tabs, which allows remote attackers to access chrome:i URIs, or read arbitrary local files via manipulations involving a series of URIs that is not entirely handled by a vector application, as exploited in conjunction with CVE-2008-2540. NOTE: this issue exists because of an insufficient fix for CVE-2005-2267.Enginsight
Vendor | Product | Version |
---|---|---|
mozilla | firefox | 𝑥 ≤ 2.0.0.15 |
mozilla | firefox | 0.8 |
mozilla | firefox | 0.9 |
mozilla | firefox | 0.9.1 |
mozilla | firefox | 0.9.2 |
mozilla | firefox | 0.9.3 |
mozilla | firefox | 0.10 |
mozilla | firefox | 0.10.1 |
mozilla | firefox | 1.0 |
mozilla | firefox | 1.0.1 |
mozilla | firefox | 1.0.2 |
mozilla | firefox | 1.0.3 |
mozilla | firefox | 1.0.4 |
mozilla | firefox | 1.0.5 |
mozilla | firefox | 1.0.6 |
mozilla | firefox | 1.0.7 |
mozilla | firefox | 1.0.8 |
mozilla | firefox | 1.5 |
mozilla | firefox | 1.5.0.1 |
mozilla | firefox | 1.5.0.2 |
mozilla | firefox | 1.5.0.3 |
mozilla | firefox | 1.5.0.4 |
mozilla | firefox | 1.5.0.5 |
mozilla | firefox | 1.5.0.6 |
mozilla | firefox | 1.5.0.7 |
mozilla | firefox | 1.5.0.8 |
mozilla | firefox | 1.5.0.9 |
mozilla | firefox | 1.5.0.10 |
mozilla | firefox | 1.5.0.11 |
mozilla | firefox | 1.5.0.12 |
mozilla | firefox | 1.5.1 |
mozilla | firefox | 1.5.2 |
mozilla | firefox | 1.5.3 |
mozilla | firefox | 1.5.4 |
mozilla | firefox | 1.5.5 |
mozilla | firefox | 1.5.6 |
mozilla | firefox | 1.5.7 |
mozilla | firefox | 1.5.8 |
mozilla | firefox | 1.8 |
mozilla | firefox | 2.0 |
mozilla | firefox | 2.0.0.1 |
mozilla | firefox | 2.0.0.2 |
mozilla | firefox | 2.0.0.3 |
mozilla | firefox | 2.0.0.4 |
mozilla | firefox | 2.0.0.5 |
mozilla | firefox | 2.0.0.6 |
mozilla | firefox | 2.0.0.7 |
mozilla | firefox | 2.0.0.8 |
mozilla | firefox | 2.0.0.9 |
mozilla | firefox | 2.0.0.10 |
mozilla | firefox | 2.0.0.11 |
mozilla | firefox | 2.0.0.12 |
mozilla | firefox | 2.0.0.13 |
mozilla | firefox | 2.0.0.14 |
mozilla | firefox | 2.0_.1:_.1 |
mozilla | firefox | 2.0_.4:_.4 |
mozilla | firefox | 2.0_.5:_.5 |
mozilla | firefox | 2.0_.6:_.6 |
mozilla | firefox | 2.0_.7:_.7 |
mozilla | firefox | 2.0_.9:_.9 |
mozilla | firefox | 2.0_.10:_.10 |
mozilla | firefox | 2.0_8:_8 |
mozilla | firefox | 3.0 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Ubuntu Product | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|
firefox |
| ||||||||||
firefox-3.0 |
| ||||||||||
iceape |
| ||||||||||
icedove |
| ||||||||||
iceweasel |
| ||||||||||
mozilla-thunderbird |
| ||||||||||
seamonkey |
| ||||||||||
thunderbird |
| ||||||||||
xulrunner |
| ||||||||||
xulrunner-1.9 |
|
Common Weakness Enumeration