CVE-2008-2806: Input Validation
Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 on Mac OS X allow remote attackers to bypass the Same Origin Policy and create arbitrary socket connections via a crafted Java applet, related to the Java Embedding Plugin (JEP) and Java LiveConnect.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-2806?
CVE-2008-2806 is considered a critical vulnerability because it allows remote attackers to bypass the Same Origin Policy.
How do I fix CVE-2008-2806?
To fix CVE-2008-2806, update Mozilla Firefox to version 2.0.0.15 or later and SeaMonkey to version 1.1.10 or later.
Which versions of software are affected by CVE-2008-2806?
CVE-2008-2806 affects Mozilla Firefox versions prior to 2.0.0.15, SeaMonkey versions before 1.1.10, and specific versions of Thunderbird.
What types of attacks can exploit CVE-2008-2806?
Attackers can exploit CVE-2008-2806 to create arbitrary socket connections through crafted Java applets.
Is there a workaround for CVE-2008-2806?
There is no known workaround for CVE-2008-2806 other than upgrading to the latest version of the affected software.