CVE-2008-4060: High severity mozilla seamonkey vulnerability
Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allow remote attackers to create documents that lack script-handling objects, and execute arbitrary code with chrome privileges, via vectors related to (1) the document.loadBindingDocument function and (2) XSLT.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-4060?
CVE-2008-4060 is considered a critical vulnerability as it allows remote attackers to execute arbitrary code with elevated privileges.
How do I fix CVE-2008-4060?
To fix CVE-2008-4060, upgrade to Mozilla Firefox version 2.0.0.17 or later, Thunderbird version 2.0.0.17 or later, and SeaMonkey version 1.1.12 or later.
Which versions of Firefox are affected by CVE-2008-4060?
Mozilla Firefox versions prior to 2.0.0.17 and all versions of 3.x before 3.0.2 are affected by CVE-2008-4060.
Can CVE-2008-4060 affect Thunderbird users?
Yes, CVE-2008-4060 affects Thunderbird users running versions before 2.0.0.17.
Is there a workaround for CVE-2008-4060?
The best approach to mitigate CVE-2008-4060 is to update to the latest versions of the affected software.