CVE
- Id
- 30710
- CVE No.
- CVE-2008-0593
- Status
- Candidate
- Description
- Gecko-based browsers, including Mozilla Firefox before 2.0.0.12 and SeaMonkey before 1.1.8, modify the .href property of stylesheet DOM nodes to the final URI of a 302 redirect, which might allow remote attackers to bypass the Same Origin Policy and read sensitive information from the original URL, such as with Single-Signon systems.
- Phase
- Assigned (20080205)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
Id | CVE Id | CVE No. | Reference | Actions |
---|---|---|---|---|
326870 | 30710 | CVE-2008-0593 | BUGTRAQ:20080209 rPSA-2008-0051-1 firefox | View |
326871 | 30710 | CVE-2008-0593 | URL:http://www.securityfocus.com/archive/1/archive/1/487826/100/0/threaded | View |
326872 | 30710 | CVE-2008-0593 | CONFIRM:http://www.mozilla.org/security/announce/2008/mfsa2008-10.html | View |
326873 | 30710 | CVE-2008-0593 | CONFIRM:https://bugzilla.mozilla.org/show_bug.cgi?id=397427 | View |
326874 | 30710 | CVE-2008-0593 | CONFIRM:http://wiki.rpath.com/Advisories:rPSA-2008-0051 | View |
326875 | 30710 | CVE-2008-0593 | CONFIRM:http://browser.netscape.com/releasenotes/ | View |
326876 | 30710 | CVE-2008-0593 | CONFIRM:http://support.novell.com/techcenter/psdb/6251b18e050302ebe7fe74294b55c818.html | View |
326877 | 30710 | CVE-2008-0593 | DEBIAN:DSA-1484 | View |
326878 | 30710 | CVE-2008-0593 | URL:http://www.debian.org/security/2008/dsa-1484 | View |
326879 | 30710 | CVE-2008-0593 | DEBIAN:DSA-1485 | View |
326880 | 30710 | CVE-2008-0593 | URL:http://www.debian.org/security/2008/dsa-1485 | View |
326881 | 30710 | CVE-2008-0593 | DEBIAN:DSA-1489 | View |
326882 | 30710 | CVE-2008-0593 | URL:http://www.debian.org/security/2008/dsa-1489 | View |
326883 | 30710 | CVE-2008-0593 | DEBIAN:DSA-1506 | View |
326884 | 30710 | CVE-2008-0593 | URL:http://www.debian.org/security/2008/dsa-1506 | View |
326885 | 30710 | CVE-2008-0593 | FEDORA:FEDORA-2008-1435 | View |
326886 | 30710 | CVE-2008-0593 | URL:https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00274.html | View |
326887 | 30710 | CVE-2008-0593 | FEDORA:FEDORA-2008-1459 | View |
326888 | 30710 | CVE-2008-0593 | URL:https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00309.html | View |
326889 | 30710 | CVE-2008-0593 | FEDORA:FEDORA-2008-1535 | View |
326890 | 30710 | CVE-2008-0593 | URL:https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00381.html | View |
326891 | 30710 | CVE-2008-0593 | FEDORA:FEDORA-2008-2060 | View |
326892 | 30710 | CVE-2008-0593 | URL:https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00905.html | View |
326893 | 30710 | CVE-2008-0593 | FEDORA:FEDORA-2008-2118 | View |
326894 | 30710 | CVE-2008-0593 | URL:https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00946.html | View |
326895 | 30710 | CVE-2008-0593 | GENTOO:GLSA-200805-18 | View |
326896 | 30710 | CVE-2008-0593 | URL:http://www.gentoo.org/security/en/glsa/glsa-200805-18.xml | View |
326897 | 30710 | CVE-2008-0593 | MANDRIVA:MDVSA-2008:048 | View |
326898 | 30710 | CVE-2008-0593 | URL:http://www.mandriva.com/security/advisories?name=MDVSA-2008:048 | View |
326899 | 30710 | CVE-2008-0593 | REDHAT:RHSA-2008:0103 | View |
326900 | 30710 | CVE-2008-0593 | URL:http://www.redhat.com/support/errata/RHSA-2008-0103.html | View |
326901 | 30710 | CVE-2008-0593 | REDHAT:RHSA-2008:0104 | View |
326902 | 30710 | CVE-2008-0593 | URL:http://www.redhat.com/support/errata/RHSA-2008-0104.html | View |
326903 | 30710 | CVE-2008-0593 | REDHAT:RHSA-2008:0105 | View |
326904 | 30710 | CVE-2008-0593 | URL:http://www.redhat.com/support/errata/RHSA-2008-0105.html | View |
326905 | 30710 | CVE-2008-0593 | SUNALERT:238492 | View |
326906 | 30710 | CVE-2008-0593 | URL:http://sunsolve.sun.com/search/document.do?assetkey=1-26-238492-1 | View |
326907 | 30710 | CVE-2008-0593 | SUSE:SUSE-SA:2008:008 | View |
326908 | 30710 | CVE-2008-0593 | URL:http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00006.html | View |
326909 | 30710 | CVE-2008-0593 | UBUNTU:USN-576-1 | View |
326910 | 30710 | CVE-2008-0593 | URL:http://www.ubuntu.com/usn/usn-576-1 | View |
326911 | 30710 | CVE-2008-0593 | BID:27683 | View |
326912 | 30710 | CVE-2008-0593 | URL:http://www.securityfocus.com/bid/27683 | View |
326913 | 30710 | CVE-2008-0593 | OVAL:oval:org.mitre.oval:def:10075 | View |
326914 | 30710 | CVE-2008-0593 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10075 | View |
326915 | 30710 | CVE-2008-0593 | VUPEN:ADV-2008-0453 | View |
326916 | 30710 | CVE-2008-0593 | URL:http://www.vupen.com/english/advisories/2008/0453/references | View |
326917 | 30710 | CVE-2008-0593 | VUPEN:ADV-2008-0627 | View |
326918 | 30710 | CVE-2008-0593 | URL:http://www.vupen.com/english/advisories/2008/0627/references | View |
326919 | 30710 | CVE-2008-0593 | VUPEN:ADV-2008-1793 | View |
326920 | 30710 | CVE-2008-0593 | URL:http://www.vupen.com/english/advisories/2008/1793/references | View |
326921 | 30710 | CVE-2008-0593 | SECTRACK:1019341 | View |
326922 | 30710 | CVE-2008-0593 | URL:http://www.securitytracker.com/id?1019341 | View |
326923 | 30710 | CVE-2008-0593 | SECUNIA:28818 | View |
326924 | 30710 | CVE-2008-0593 | URL:http://secunia.com/advisories/28818 | View |
326925 | 30710 | CVE-2008-0593 | SECUNIA:28754 | View |
326926 | 30710 | CVE-2008-0593 | URL:http://secunia.com/advisories/28754 | View |
326927 | 30710 | CVE-2008-0593 | SECUNIA:28758 | View |
326928 | 30710 | CVE-2008-0593 | URL:http://secunia.com/advisories/28758 | View |
326929 | 30710 | CVE-2008-0593 | SECUNIA:28766 | View |
326930 | 30710 | CVE-2008-0593 | URL:http://secunia.com/advisories/28766 | View |
326931 | 30710 | CVE-2008-0593 | SECUNIA:28815 | View |
326932 | 30710 | CVE-2008-0593 | URL:http://secunia.com/advisories/28815 | View |
326933 | 30710 | CVE-2008-0593 | SECUNIA:28839 | View |
326934 | 30710 | CVE-2008-0593 | URL:http://secunia.com/advisories/28839 | View |
326935 | 30710 | CVE-2008-0593 | SECUNIA:28864 | View |
326936 | 30710 | CVE-2008-0593 | URL:http://secunia.com/advisories/28864 | View |
326937 | 30710 | CVE-2008-0593 | SECUNIA:28865 | View |
326938 | 30710 | CVE-2008-0593 | URL:http://secunia.com/advisories/28865 | View |
326939 | 30710 | CVE-2008-0593 | SECUNIA:28877 | View |
326940 | 30710 | CVE-2008-0593 | URL:http://secunia.com/advisories/28877 | View |
326941 | 30710 | CVE-2008-0593 | SECUNIA:28879 | View |
326942 | 30710 | CVE-2008-0593 | URL:http://secunia.com/advisories/28879 | View |
326943 | 30710 | CVE-2008-0593 | SECUNIA:28924 | View |
326944 | 30710 | CVE-2008-0593 | URL:http://secunia.com/advisories/28924 | View |
326945 | 30710 | CVE-2008-0593 | SECUNIA:28939 | View |
326946 | 30710 | CVE-2008-0593 | URL:http://secunia.com/advisories/28939 | View |
326947 | 30710 | CVE-2008-0593 | SECUNIA:28958 | View |
326948 | 30710 | CVE-2008-0593 | URL:http://secunia.com/advisories/28958 | View |
326949 | 30710 | CVE-2008-0593 | SECUNIA:29049 | View |
326950 | 30710 | CVE-2008-0593 | URL:http://secunia.com/advisories/29049 | View |
326951 | 30710 | CVE-2008-0593 | SECUNIA:29086 | View |
326952 | 30710 | CVE-2008-0593 | URL:http://secunia.com/advisories/29086 | View |
326953 | 30710 | CVE-2008-0593 | SECUNIA:29167 | View |
326954 | 30710 | CVE-2008-0593 | URL:http://secunia.com/advisories/29167 | View |
326955 | 30710 | CVE-2008-0593 | SECUNIA:29567 | View |
326956 | 30710 | CVE-2008-0593 | URL:http://secunia.com/advisories/29567 | View |
326957 | 30710 | CVE-2008-0593 | SECUNIA:30327 | View |
326958 | 30710 | CVE-2008-0593 | URL:http://secunia.com/advisories/30327 | View |
326959 | 30710 | CVE-2008-0593 | SECUNIA:30620 | View |
Related JVN
Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
---|---|---|---|---|---|---|---|---|---|
45836 | JVNDB-2008-001146 | CUPS における IPP パケット処理の不備によるサービス運用妨害 (DoS) の脆弱性 | CUPS には、IPP パケットの処理に不備があるために、開放されたメモリ領域を使用することによる、サービス運用妨害 (DoS) 状態となる脆弱性が存在します。 | CVE-2008-0597 | 30710 | 5 | http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-001146.html | View |