Security Advisory

CVE-2008-5503

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2008-12-17 23:00:00
Last updated 2024-08-07 10:56:46
Assigner redhat
State PUBLISHED

Description

The loadBindingDocument function in Mozilla Firefox 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 does not perform any security checks related to the same-domain policy, which allows remote attackers to read or access data from other domains via crafted XBL bindings.