CVE-2008-0593

N/A Unknown
Published: February 09, 2008 Modified: April 23, 2026
View on NVD

Description

Gecko-based browsers, including Mozilla Firefox before 2.0.0.12 and SeaMonkey before 1.1.8, modify the .href property of stylesheet DOM nodes to the final URI of a 302 redirect, which might allow remote attackers to bypass the Same Origin Policy and read sensitive information from the original URL, such as with Single-Signon systems.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://secunia.com/advisories/28754
Source: secalert@redhat.com
Vendor Advisory
http://secunia.com/advisories/28758
Source: secalert@redhat.com
Vendor Advisory
http://secunia.com/advisories/28766
Source: secalert@redhat.com
Vendor Advisory
http://secunia.com/advisories/28815
Source: secalert@redhat.com
Vendor Advisory
http://secunia.com/advisories/28818
Source: secalert@redhat.com
Vendor Advisory
http://secunia.com/advisories/28839
Source: secalert@redhat.com
Vendor Advisory
http://secunia.com/advisories/28864
Source: secalert@redhat.com
Vendor Advisory
http://secunia.com/advisories/28865
Source: secalert@redhat.com
Vendor Advisory
http://secunia.com/advisories/28877
Source: secalert@redhat.com
Vendor Advisory
http://secunia.com/advisories/28879
Source: secalert@redhat.com
Vendor Advisory
http://secunia.com/advisories/28924
Source: secalert@redhat.com
Vendor Advisory
http://secunia.com/advisories/28939
Source: secalert@redhat.com
Vendor Advisory
http://secunia.com/advisories/28958
Source: secalert@redhat.com
Vendor Advisory
http://secunia.com/advisories/29049
Source: secalert@redhat.com
Vendor Advisory
http://secunia.com/advisories/29086
Source: secalert@redhat.com
Vendor Advisory
http://secunia.com/advisories/29167
Source: secalert@redhat.com
Vendor Advisory
http://secunia.com/advisories/29567
Source: secalert@redhat.com
Vendor Advisory
http://secunia.com/advisories/30327
Source: secalert@redhat.com
Vendor Advisory
http://secunia.com/advisories/30620
Source: secalert@redhat.com
Vendor Advisory
http://www.redhat.com/support/errata/RHSA-2008-0103.html
Source: secalert@redhat.com
Vendor Advisory
http://www.redhat.com/support/errata/RHSA-2008-0104.html
Source: secalert@redhat.com
Vendor Advisory
http://www.redhat.com/support/errata/RHSA-2008-0105.html
Source: secalert@redhat.com
Vendor Advisory
http://www.securityfocus.com/bid/27683
Source: secalert@redhat.com
http://www.ubuntu.com/usn/usn-576-1
Source: secalert@redhat.com
http://www.vupen.com/english/advisories/2008/0453/references
Source: secalert@redhat.com
Vendor Advisory
http://www.vupen.com/english/advisories/2008/0627/references
Source: secalert@redhat.com
Vendor Advisory
http://www.vupen.com/english/advisories/2008/1793/references
Source: secalert@redhat.com
Vendor Advisory
http://browser.netscape.com/releasenotes/
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/28754
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://secunia.com/advisories/28758
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://secunia.com/advisories/28766
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://secunia.com/advisories/28815
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://secunia.com/advisories/28818
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://secunia.com/advisories/28839
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://secunia.com/advisories/28864
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://secunia.com/advisories/28865
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://secunia.com/advisories/28877
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://secunia.com/advisories/28879
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://secunia.com/advisories/28924
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://secunia.com/advisories/28939
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://secunia.com/advisories/28958
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://secunia.com/advisories/29049
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://secunia.com/advisories/29086
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://secunia.com/advisories/29167
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://secunia.com/advisories/29567
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://secunia.com/advisories/30327
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://secunia.com/advisories/30620
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://sunsolve.sun.com/search/document.do?assetkey=1-26-238492-1
Source: af854a3a-2127-422b-91ae-364da2661108
http://wiki.rpath.com/Advisories:rPSA-2008-0051
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.debian.org/security/2008/dsa-1484
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.debian.org/security/2008/dsa-1485
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.debian.org/security/2008/dsa-1489
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.debian.org/security/2008/dsa-1506
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.gentoo.org/security/en/glsa/glsa-200805-18.xml
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.mandriva.com/security/advisories?name=MDVSA-2008:048
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.mozilla.org/security/announce/2008/mfsa2008-10.html
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.redhat.com/support/errata/RHSA-2008-0103.html
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://www.redhat.com/support/errata/RHSA-2008-0104.html
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://www.redhat.com/support/errata/RHSA-2008-0105.html
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://www.securityfocus.com/archive/1/487826/100/0/threaded
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/bid/27683
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securitytracker.com/id?1019341
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.ubuntu.com/usn/usn-576-1
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2008/0453/references
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://www.vupen.com/english/advisories/2008/0627/references
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://www.vupen.com/english/advisories/2008/1793/references
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
https://bugzilla.mozilla.org/show_bug.cgi?id=397427
Source: af854a3a-2127-422b-91ae-364da2661108

96 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
1.1%
78th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

mozilla