CVE-2008-5503: Low severity Mozilla SeaMonkey vulnerability
The loadBindingDocument function in Mozilla Firefox 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 does not perform any security checks related to the same-domain policy, which allows remote attackers to read or access data from other domains via crafted XBL bindings.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-5503?
CVE-2008-5503 has a medium severity rating.
How do I fix CVE-2008-5503?
To fix CVE-2008-5503, update to Mozilla Firefox version 2.0.0.19 or later, Thunderbird version 2.0.0.19 or later, or SeaMonkey version 1.1.14 or later.
Which software versions are affected by CVE-2008-5503?
CVE-2008-5503 affects Mozilla Firefox versions before 2.0.0.19, Thunderbird versions before 2.0.0.19, and SeaMonkey versions before 1.1.14.
What types of attacks does CVE-2008-5503 allow?
CVE-2008-5503 allows remote attackers to read or access data from other domains through crafted XBL bindings.
Is CVE-2008-5503 a browser vulnerability?
Yes, CVE-2008-5503 is a vulnerability in the browsers Mozilla Firefox, Thunderbird, and SeaMonkey.