CVE-2008-4065: XSS
Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allow remote attackers to bypass cross-site scripting (XSS) protection mechanisms and conduct XSS attacks via byte order mark (BOM) characters that are removed from JavaScript code before execution, aka "Stripped BOM characters bug."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-4065?
The severity of CVE-2008-4065 is classified as low, but it can still allow significant XSS attacks.
How do I fix CVE-2008-4065?
To fix CVE-2008-4065, upgrade to Mozilla Firefox version 2.0.0.17 or later, Thunderbird version 2.0.0.17 or later, or SeaMonkey version 1.1.12 or later.
What software is affected by CVE-2008-4065?
CVE-2008-4065 affects Mozilla Firefox versions before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12.
Can CVE-2008-4065 be exploited remotely?
Yes, CVE-2008-4065 can be exploited remotely by attackers through crafted JavaScript code.
What type of vulnerability is CVE-2008-4065?
CVE-2008-4065 is a cross-site scripting (XSS) vulnerability that bypasses existing XSS protection mechanisms.