peter bassill · operator
$ cve CVE-2008-0418 JSON

CVE-2008-0418 EXPLOIT

4.3
MEDIUM · CVSS 2.0 · EPSS 8.6% (pctl 95)

Patch early

A public exploit exists.

Description

Directory traversal vulnerability in Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8, when using "flat" addons, allows remote attackers to read arbitrary Javascript, image, and stylesheet files via the chrome: URI scheme, as demonstrated by stealing session information from sessionstore.js.

Scoring

CVSS4.3 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
EPSS8.63% — more likely to be exploited than 95% of all CVEs
WeaknessCWE-22
On CISA KEVno
Public exploityes
Published2008-02-08
Last modified2026-06-16

Affected (3)

VendorProduct
mozillafirefox
mozillaseamonkey
mozillathunderbird

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD