Skip to content
Appaloosa Scout

Vulnerability · NVD

CVE-2008-2803

N/A

The mozIJSSubScriptLoader.LoadScript function in Mozilla Firefox before 2.0.0.15, Thunderbird 2.0.0.14 and earlier, and SeaMonkey before 1.1.10 does not apply XPCNativeWrappers to scripts loaded from (1) file: URIs, (2) data: URIs, or (3) certain non-canonical chrome: URIs, which allows remote attackers to execute arbitrary code via vectors involving third-party add-ons.

EPSS 3.21% above median percentile 87.0%

Tracked apps referencing this CVE

For each app: the affected range, the fixing version, and where the tracked app stands today.

Vulnerable CPE configurations (13)
Vendor Product Versions
mozilla thunderbird
All platforms (wildcard)
≤2.0.0.14
mozilla thunderbird
All platforms (wildcard)
mozilla thunderbird
All platforms (wildcard)
mozilla thunderbird
All platforms (wildcard)
mozilla thunderbird
All platforms (wildcard)
mozilla thunderbird
All platforms (wildcard)
mozilla thunderbird
All platforms (wildcard)
mozilla thunderbird
All platforms (wildcard)
mozilla thunderbird
All platforms (wildcard)
mozilla thunderbird
All platforms (wildcard)
mozilla thunderbird
All platforms (wildcard)
mozilla thunderbird
All platforms (wildcard)
mozilla thunderbird
All platforms (wildcard)
View on NVD ↗ Advisory · secunia.com