Unrated severityNVD Advisory· Published Mar 28, 2008· Updated Jun 16, 2026
CVE-2008-1240
CVE-2008-1240
Description
LiveConnect in Mozilla Firefox before 2.0.0.13 and SeaMonkey before 1.1.9 does not properly parse the content origin for jar: URIs before sending them to the Java plugin, which allows remote attackers to access arbitrary ports on the local machine. NOTE: this is closely related to CVE-2008-1195.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*range: <=2.0.0.12
- (no CPE)range: <2.0.0.13
cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:*range: <=1.1.8
- (no CPE)range: <1.1.9
Patches
Vulnerability mechanics
References
26- www.us-cert.gov/cas/techalerts/TA08-087A.htmlnvdUS Government Resource
- lists.opensuse.org/opensuse-security-announce/2008-04/msg00002.htmlnvd
- secunia.com/advisories/29526nvd
- secunia.com/advisories/29539nvd
- secunia.com/advisories/29541nvd
- secunia.com/advisories/29547nvd
- secunia.com/advisories/29558nvd
- secunia.com/advisories/29560nvd
- secunia.com/advisories/29616nvd
- secunia.com/advisories/29645nvd
- secunia.com/advisories/30327nvd
- secunia.com/advisories/30620nvd
- sunsolve.sun.com/search/document.donvd
- wiki.rpath.com/wiki/Advisories:rPSA-2008-0128nvd
- www.debian.org/security/2008/dsa-1532nvd
- www.debian.org/security/2008/dsa-1534nvd
- www.debian.org/security/2008/dsa-1535nvd
- www.gentoo.org/security/en/glsa/glsa-200805-18.xmlnvd
- www.mandriva.com/security/advisoriesnvd
- www.mozilla.org/security/announce/2008/mfsa2008-18.htmlnvd
- www.securityfocus.com/archive/1/490196/100/0/threadednvd
- www.securityfocus.com/bid/28448nvd
- www.ubuntu.com/usn/usn-592-1nvd
- www.vupen.com/english/advisories/2008/0998/referencesnvd
- www.vupen.com/english/advisories/2008/1793/referencesnvd
- exchange.xforce.ibmcloud.com/vulnerabilities/41458nvd
News mentions
0No linked articles in our index yet.