Sploitus

CVE-2008-5024

No indexed exploits for CVE-2008-5024 yet

Mozilla Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 do not properly escape quote characters used for XML processing, which allows remote attackers to conduct XML injection attacks via the default namespace in an E4X document.

Mozilla Firefox
< 2.0.0.18, 3.0.4
Mozilla Seamonkey
< 1.1.13
Mozilla Thunderbird
< 2.0.0.18
Fix
Available
CVSS 2.0
7.5 HIGH
EPSS
3.6% (88th percentile)
Weakness
CWE-91
NVD status
Modified
Published
2008-11-13
CVE-2008-5024 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2008-5024 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2008-5024 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.