CVE-2008-2801: High severity firefox vulnerability
Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 do not properly implement JAR signing, which allows remote attackers to execute arbitrary code via (1) injection of JavaScript into documents within a JAR archive or (2) a JAR archive that uses relative URLs to JavaScript files.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-2801?
CVE-2008-2801 is considered a critical vulnerability as it allows remote code execution.
How do I fix CVE-2008-2801?
To fix CVE-2008-2801, users should update Mozilla Firefox to version 2.0.0.15 or later and SeaMonkey to version 1.1.10 or later.
What software is affected by CVE-2008-2801?
CVE-2008-2801 affects Mozilla Firefox versions before 2.0.0.15 and SeaMonkey versions before 1.1.10.
What types of attacks can exploit CVE-2008-2801?
CVE-2008-2801 can be exploited through injection of malicious JavaScript into JAR archives.
Is CVE-2008-2801 still a concern for modern browsers?
CVE-2008-2801 is not a concern for modern browsers as it pertains to outdated versions of Mozilla Firefox and SeaMonkey.