VYPR
Unrated severityNVD Advisory· Published Dec 17, 2008· Updated Apr 23, 2026

CVE-2008-5508

CVE-2008-5508

Description

Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 does not properly parse URLs with leading whitespace or control characters, which might allow remote attackers to misrepresent URLs and simplify phishing attacks.

Affected products

9
  • cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
    Range: >=2.0,<2.0.0.19
  • cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:*
    Range: >=1.0,<1.1.14
  • cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
    Range: >=2.0,<2.0.0.19
  • cpe:2.3:o:canonical:ubuntu_linux:6.06:*:*:*:lts:*:*:*+ 3 more
    • cpe:2.3:o:canonical:ubuntu_linux:6.06:*:*:*:lts:*:*:*
    • cpe:2.3:o:canonical:ubuntu_linux:7.10:*:*:*:*:*:*:*
    • cpe:2.3:o:canonical:ubuntu_linux:8.04:*:*:*:lts:*:*:*
    • cpe:2.3:o:canonical:ubuntu_linux:8.10:*:*:*:*:*:*:*
  • cpe:2.3:o:debian:debian_linux:4.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:debian:debian_linux:4.0:*:*:*:*:*:*:*
    • cpe:2.3:o:debian:debian_linux:5.0:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

41

News mentions

0

No linked articles in our index yet.