CVE-2008-5508
EUVD-2008-548517.12.2008, 23:30
Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 does not properly parse URLs with leading whitespace or control characters, which might allow remote attackers to misrepresent URLs and simplify phishing attacks.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| mozilla | firefox | 2.0 ≤ 𝑥 < 2.0.0.19 |
| mozilla | firefox | 3.0 ≤ 𝑥 < 3.0.5 |
| mozilla | seamonkey | 1.0 ≤ 𝑥 < 1.1.14 |
| mozilla | thunderbird | 2.0 ≤ 𝑥 < 2.0.0.19 |
| canonical | ubuntu_linux | 6.06 |
| canonical | ubuntu_linux | 7.10 |
| canonical | ubuntu_linux | 8.04 |
| canonical | ubuntu_linux | 8.10 |
| debian | debian_linux | 4.0 |
| debian | debian_linux | 5.0 |
𝑥
= Vulnerable software versions
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| firefox |
| ||||||||||||||||||
| firefox-3.0 |
| ||||||||||||||||||
| iceape |
| ||||||||||||||||||
| mozilla-thunderbird |
| ||||||||||||||||||
| seamonkey |
| ||||||||||||||||||
| thunderbird |
| ||||||||||||||||||
| xulrunner |
| ||||||||||||||||||
| xulrunner-1.9 |
|
Common Weakness Enumeration
References