vendor:
Firefox
by:
Dominic Chell
7.5
CVSS
HIGH
UTF-8 URL overflow vulnerability
119
CWE
Product Name: Firefox
Affected Version From: 2.0.0.16
Affected Version To: 2.0.0.16
Patch Exists: YES
Related CWE: CVE-2008-0016
CPE: a:mozilla:firefox:2.0.0.16
Metasploit:
https://www.rapid7.com/db/vulnerabilities/vmsa-2008-0016-cve-2008-4279-player/, https://www.rapid7.com/db/vulnerabilities/vmsa-2008-0016-cve-2008-4279-workstation/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2008-0908/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2008-0882/, https://www.rapid7.com/db/vulnerabilities/mozilla-seamonkey-cve-2008-0016/, https://www.rapid7.com/db/vulnerabilities/mozilla-thunderbird-cve-2008-0016/, https://www.rapid7.com/db/vulnerabilities/centos_linux-cve-2008-0016/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2008-0016/, https://www.rapid7.com/db/vulnerabilities/mfsa2008-37-cve-2008-0016/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2008-0016/, https://www.rapid7.com/db/vulnerabilities/windows-mozilla-firefox-multiple-vulns-2-0-0-17-and-3-0-2/
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP3 x86
2009
FireFox 2.0.0.16 Windows XP SP3 x86 Remote Exploit
Exploits the UTF-8 URL overflow vulnerability described in CVE-2008-0016. As of September 2009 there are no public exploits for this vulnerability. However, according to securityfocus an exploit is available in both Canvas and Core Impact.
Mitigation:
Apply the latest security patches and updates to the system.