AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2008-5024

HIGH · CVSS 7.5 EPSS 3.64%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2008-11-13 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2008-5024
Severity
HIGH
CVSS
7.5
EPSS
3.64%
Firefox

Original NVD Description

Mozilla Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 do not properly escape quote characters used for XML processing, which allows remote attackers to conduct XML injection attacks via the default namespace in an E4X document.