Unrated severityNVD Advisory· Published Jul 7, 2008· Updated Apr 23, 2026
CVE-2008-2806
CVE-2008-2806
Description
Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 on Mac OS X allow remote attackers to bypass the Same Origin Policy and create arbitrary socket connections via a crafted Java applet, related to the Java Embedding Plugin (JEP) and Java LiveConnect.
Affected products
36cpe:2.3:a:mozilla:firefox:2.0:*:*:*:*:*:*:*+ 17 more
- cpe:2.3:a:mozilla:firefox:2.0:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:firefox:2.0.0.11:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:firefox:2.0.0.12:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:firefox:2.0.0.13:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:firefox:2.0.0.14:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:firefox:2.0.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:firefox:2.0.0.3:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:firefox:2.0_.1:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:firefox:2.0_.10:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:firefox:2.0_.4:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:firefox:2.0_.5:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:firefox:2.0_.6:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:firefox:2.0_.7:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:firefox:2.0_8:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:firefox:2.0_.9:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:firefox:2.0:beta_1:*:*:*:*:*:*
- cpe:2.3:a:mozilla:firefox:2.0:rc2:*:*:*:*:*:*
- cpe:2.3:a:mozilla:firefox:2.0:rc3:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:1.1.1:*:*:*:*:*:*:*+ 9 more
- cpe:2.3:a:mozilla:seamonkey:1.1.1:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:seamonkey:1.1.2:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:seamonkey:1.1.3:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:seamonkey:1.1.4:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:seamonkey:1.1.5:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:seamonkey:1.1.6:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:seamonkey:1.1.7:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:seamonkey:1.1.8:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:seamonkey:1.1.9:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:seamonkey:1.1:beta:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:2.0_.12:*:*:*:*:*:*:*+ 7 more
- cpe:2.3:a:mozilla:thunderbird:2.0_.12:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:thunderbird:2.0_.13:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:thunderbird:2.0_.14:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:thunderbird:2.0_.4:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:thunderbird:2.0_.5:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:thunderbird:2.0_.6:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:thunderbird:2.0_8:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:thunderbird:2.0_.9:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
22- secunia.com/advisories/30911nvdVendor Advisory
- lists.opensuse.org/opensuse-security-announce/2008-07/msg00004.htmlnvd
- secunia.com/advisories/30898nvd
- secunia.com/advisories/31005nvd
- secunia.com/advisories/31008nvd
- secunia.com/advisories/31021nvd
- secunia.com/advisories/31023nvd
- secunia.com/advisories/31076nvd
- slackware.com/security/viewer.phpnvd
- slackware.com/security/viewer.phpnvd
- wiki.rpath.com/Advisories:rPSA-2008-0216nvd
- www.mozilla.org/projects/security/known-vulnerabilities.htmlnvd
- www.mozilla.org/security/announce/2008/mfsa2008-28.htmlnvd
- www.securityfocus.com/archive/1/494080/100/0/threadednvd
- www.securityfocus.com/bid/30038nvd
- www.securitytracker.com/idnvd
- www.ubuntu.com/usn/usn-619-1nvd
- www.vupen.com/english/advisories/2008/1993/referencesnvd
- bugzilla.mozilla.org/show_bug.cginvd
- issues.rpath.com/browse/RPL-2646nvd
- www.redhat.com/archives/fedora-package-announce/2008-July/msg00288.htmlnvd
- www.redhat.com/archives/fedora-package-announce/2008-July/msg00295.htmlnvd
News mentions
0No linked articles in our index yet.