{"api_version":"1","generated_at":"2026-07-23T03:47:36+00:00","cve":"CVE-2008-4582","urls":{"html":"https://cve.report/CVE-2008-4582","api":"https://cve.report/api/cve/CVE-2008-4582.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2008-4582","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2008-4582"},"summary":{"title":"CVE-2008-4582","description":"Mozilla Firefox 3.0.1 through 3.0.3, Firefox 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13, when running on Windows, do not properly identify the context of Windows .url shortcut files, which allows user-assisted remote attackers to bypass the Same Origin Policy and obtain sensitive information via an HTML document that is directly accessible through a filesystem, as demonstrated by documents in (1) local folders, (2) Windows share folders, and (3) RAR archives, and as demonstrated by IFRAMEs referencing shortcuts that point to (a) about:cache?device=memory and (b) about:cache?device=disk, a variant of CVE-2008-2810.","state":"PUBLISHED","assigner":"mitre","published_at":"2008-10-15 20:08:02","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-264","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:N/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://secunia.com/advisories/32845","name":"http://secunia.com/advisories/32845","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"],"title":"Debian update for xulrunner - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.debian.org/security/2009/dsa-1696","name":"http://www.debian.org/security/2009/dsa-1696","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Debian -- Security Information -- DSA-1696-1 icedove","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2009/0977","name":"http://www.vupen.com/english/advisories/2009/0977","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Not Applicable"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://sunsolve.sun.com/search/document.do?assetkey=1-26-256408-1","name":"http://sunsolve.sun.com/search/document.do?assetkey=1-26-256408-1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"","mime":"","httpstatus":"-1","archivestatus":"404"},{"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=455311","name":"https://bugzilla.mozilla.org/show_bug.cgi?id=455311","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking"],"title":"455311 – (CVE-2008-4582) [FIX]mid-autumn festival vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://liudieyu0.blog124.fc2.com/blog-entry-6.html","name":"http://liudieyu0.blog124.fc2.com/blog-entry-6.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"LIUDIEYU[0]　 Firefox Privacy Broken If Used to Open Web Page File","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://securitytracker.com/alerts/2008/Nov/1021212.html","name":"http://securitytracker.com/alerts/2008/Nov/1021212.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"(Mozilla Issues Fix for SeaMonkey) Mozilla Firefox '.url' Windows Shortcut Files May Let Remote Users Obtain Potentially Sensitive Information - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/497091/100/0/threaded","name":"http://www.securityfocus.com/archive/1/497091/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.debian.org/security/2008/dsa-1669","name":"http://www.debian.org/security/2008/dsa-1669","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Debian -- Security Information -- DSA-1669-1 xulrunner","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/32853","name":"http://secunia.com/advisories/32853","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"],"title":"Debian update for iceweasel - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securityreason.com/securityalert/4416","name":"http://securityreason.com/securityalert/4416","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"CXSecurity - IDS","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.debian.org/security/2008/dsa-1671","name":"http://www.debian.org/security/2008/dsa-1671","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Debian -- Security Information -- DSA-1671-1 iceweasel","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/31611","name":"http://www.securityfocus.com/bid/31611","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"Mozilla Firefox Internet Shortcut Same Origin Policy Violation Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.redhat.com/archives/fedora-package-announce/2008-November/msg00366.html","name":"https://www.redhat.com/archives/fedora-package-announce/2008-November/msg00366.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Not Applicable"],"title":"[SECURITY] Fedora 8 Update: firefox-2.0.0.18-1.fc8","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.mozilla.org/security/announce/2008/mfsa2008-47.html","name":"http://www.mozilla.org/security/announce/2008/mfsa2008-47.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"MFSA 2008-47: Information stealing via local shortcut files","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id?1021190","name":"http://www.securitytracker.com/id?1021190","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"Mozilla Firefox '.url' Windows Shortcut Files May Let Remote Users Obtain Potentially Sensitive Information - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/45740","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/45740","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.debian.org/security/2009/dsa-1697","name":"http://www.debian.org/security/2009/dsa-1697","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Debian -- Security Information -- DSA-1697-1 iceape","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/32693","name":"http://secunia.com/advisories/32693","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"],"title":"Mozilla Firefox 2 Multiple Vulnerabilities - Secunia Advisories - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2008/2818","name":"http://www.vupen.com/english/advisories/2008/2818","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Not Applicable"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.us-cert.gov/cas/techalerts/TA08-319A.html","name":"http://www.us-cert.gov/cas/techalerts/TA08-319A.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","US Government Resource"],"title":"US-CERT Technical Cyber Security Alert TA08-319A -- Mozilla Updates for Multiple Vulnerabilities","mime":"text/xml","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/33433","name":"http://secunia.com/advisories/33433","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"],"title":"Debian update for iceape - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/32778","name":"http://secunia.com/advisories/32778","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"],"title":"Ubuntu update for firefox, firefox-3.0, and xulrunner-1.9 - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/32721","name":"http://secunia.com/advisories/32721","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"],"title":"Fedora update for firefox and xulrunner - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.redhat.com/archives/fedora-package-announce/2008-November/msg00385.html","name":"https://www.redhat.com/archives/fedora-package-announce/2008-November/msg00385.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Not Applicable"],"title":"[SECURITY] Fedora 9 Update: xulrunner-1.9.0.4-1.fc9","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/34501","name":"http://secunia.com/advisories/34501","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"],"title":"Sun Solaris Firefox Multiple Vulnerabilities - Secunia Advisories - Vulnerability Information - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/33434","name":"http://secunia.com/advisories/33434","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"],"title":"Debian update for icedove - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/31747","name":"http://www.securityfocus.com/bid/31747","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"Mozilla Firefox '.url' Shortcut Processing Information Disclosure Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://secunia.com/advisories/32684","name":"http://secunia.com/advisories/32684","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"],"title":"Fedora update for firefox - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/32192","name":"http://secunia.com/advisories/32192","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"],"title":"Firefox .url Shortcut File Information Disclosure - Secunia Advisories - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/32714","name":"http://secunia.com/advisories/32714","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"],"title":"Mozilla SeaMonkey Multiple Vulnerabilities - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://ubuntu.com/usn/usn-667-1","name":"http://ubuntu.com/usn/usn-667-1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"USN-667-1: Firefox and xulrunner vulnerabilities | Ubuntu","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2008-4582","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2008-4582","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2008","cve_id":"4582","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"debian","cpe5":"debian_linux","cpe6":"4.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"4582","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"4582","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mozilla","cpe5":"firefox","cpe6":"2.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"4582","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mozilla","cpe5":"firefox","cpe6":"2.0.0.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"4582","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mozilla","cpe5":"firefox","cpe6":"2.0.0.10","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"4582","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mozilla","cpe5":"firefox","cpe6":"2.0.0.11","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"4582","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mozilla","cpe5":"firefox","cpe6":"2.0.0.12","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"4582","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mozilla","cpe5":"firefox","cpe6":"2.0.0.13","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"4582","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mozilla","cpe5":"firefox","cpe6":"2.0.0.14","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"4582","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mozilla","cpe5":"firefox","cpe6":"2.0.0.15","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"4582","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mozilla","cpe5":"firefox","cpe6":"2.0.0.16","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"4582","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mozilla","cpe5":"firefox","cpe6":"2.0.0.17","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"4582","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mozilla","cpe5":"firefox","cpe6":"3.0.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"4582","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mozilla","cpe5":"firefox","cpe6":"3.0.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"4582","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mozilla","cpe5":"firefox","cpe6":"3.0.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T10:24:19.339Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"firefox-internet-shortcut-info-disclosure(45740)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/45740"},{"name":"DSA-1697","tags":["vendor-advisory","x_refsource_DEBIAN","x_transferred"],"url":"http://www.debian.org/security/2009/dsa-1697"},{"name":"1021190","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1021190"},{"name":"DSA-1671","tags":["vendor-advisory","x_refsource_DEBIAN","x_transferred"],"url":"http://www.debian.org/security/2008/dsa-1671"},{"name":"FEDORA-2008-9667","tags":["vendor-advisory","x_refsource_FEDORA","x_transferred"],"url":"https://www.redhat.com/archives/fedora-package-announce/2008-November/msg00366.html"},{"name":"ADV-2009-0977","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2009/0977"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=455311"},{"name":"32192","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/32192"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.mozilla.org/security/announce/2008/mfsa2008-47.html"},{"name":"1021212","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/alerts/2008/Nov/1021212.html"},{"name":"DSA-1669","tags":["vendor-advisory","x_refsource_DEBIAN","x_transferred"],"url":"http://www.debian.org/security/2008/dsa-1669"},{"name":"32778","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/32778"},{"name":"FEDORA-2008-9669","tags":["vendor-advisory","x_refsource_FEDORA","x_transferred"],"url":"https://www.redhat.com/archives/fedora-package-announce/2008-November/msg00385.html"},{"name":"33433","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/33433"},{"name":"ADV-2008-2818","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2008/2818"},{"name":"20081007 Firefox Privacy Broken If Used to Open Web Page File","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/497091/100/0/threaded"},{"name":"256408","tags":["vendor-advisory","x_refsource_SUNALERT","x_transferred"],"url":"http://sunsolve.sun.com/search/document.do?assetkey=1-26-256408-1"},{"name":"4416","tags":["third-party-advisory","x_refsource_SREASON","x_transferred"],"url":"http://securityreason.com/securityalert/4416"},{"name":"32721","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/32721"},{"name":"TA08-319A","tags":["third-party-advisory","x_refsource_CERT","x_transferred"],"url":"http://www.us-cert.gov/cas/techalerts/TA08-319A.html"},{"name":"32853","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/32853"},{"name":"DSA-1696","tags":["vendor-advisory","x_refsource_DEBIAN","x_transferred"],"url":"http://www.debian.org/security/2009/dsa-1696"},{"name":"32693","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/32693"},{"name":"32845","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/32845"},{"name":"33434","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/33434"},{"name":"32684","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/32684"},{"name":"USN-667-1","tags":["vendor-advisory","x_refsource_UBUNTU","x_transferred"],"url":"http://ubuntu.com/usn/usn-667-1"},{"name":"31747","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/31747"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://liudieyu0.blog124.fc2.com/blog-entry-6.html"},{"name":"32714","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/32714"},{"name":"31611","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/31611"},{"name":"34501","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/34501"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2008-09-26T00:00:00.000Z","descriptions":[{"lang":"en","value":"Mozilla Firefox 3.0.1 through 3.0.3, Firefox 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13, when running on Windows, do not properly identify the context of Windows .url shortcut files, which allows user-assisted remote attackers to bypass the Same Origin Policy and obtain sensitive information via an HTML document that is directly accessible through a filesystem, as demonstrated by documents in (1) local folders, (2) Windows share folders, and (3) RAR archives, and as demonstrated by IFRAMEs referencing shortcuts that point to (a) about:cache?device=memory and (b) about:cache?device=disk, a variant of CVE-2008-2810."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-11T19:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"firefox-internet-shortcut-info-disclosure(45740)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/45740"},{"name":"DSA-1697","tags":["vendor-advisory","x_refsource_DEBIAN"],"url":"http://www.debian.org/security/2009/dsa-1697"},{"name":"1021190","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1021190"},{"name":"DSA-1671","tags":["vendor-advisory","x_refsource_DEBIAN"],"url":"http://www.debian.org/security/2008/dsa-1671"},{"name":"FEDORA-2008-9667","tags":["vendor-advisory","x_refsource_FEDORA"],"url":"https://www.redhat.com/archives/fedora-package-announce/2008-November/msg00366.html"},{"name":"ADV-2009-0977","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2009/0977"},{"tags":["x_refsource_MISC"],"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=455311"},{"name":"32192","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/32192"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.mozilla.org/security/announce/2008/mfsa2008-47.html"},{"name":"1021212","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/alerts/2008/Nov/1021212.html"},{"name":"DSA-1669","tags":["vendor-advisory","x_refsource_DEBIAN"],"url":"http://www.debian.org/security/2008/dsa-1669"},{"name":"32778","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/32778"},{"name":"FEDORA-2008-9669","tags":["vendor-advisory","x_refsource_FEDORA"],"url":"https://www.redhat.com/archives/fedora-package-announce/2008-November/msg00385.html"},{"name":"33433","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/33433"},{"name":"ADV-2008-2818","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2008/2818"},{"name":"20081007 Firefox Privacy Broken If Used to Open Web Page File","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/497091/100/0/threaded"},{"name":"256408","tags":["vendor-advisory","x_refsource_SUNALERT"],"url":"http://sunsolve.sun.com/search/document.do?assetkey=1-26-256408-1"},{"name":"4416","tags":["third-party-advisory","x_refsource_SREASON"],"url":"http://securityreason.com/securityalert/4416"},{"name":"32721","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/32721"},{"name":"TA08-319A","tags":["third-party-advisory","x_refsource_CERT"],"url":"http://www.us-cert.gov/cas/techalerts/TA08-319A.html"},{"name":"32853","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/32853"},{"name":"DSA-1696","tags":["vendor-advisory","x_refsource_DEBIAN"],"url":"http://www.debian.org/security/2009/dsa-1696"},{"name":"32693","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/32693"},{"name":"32845","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/32845"},{"name":"33434","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/33434"},{"name":"32684","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/32684"},{"name":"USN-667-1","tags":["vendor-advisory","x_refsource_UBUNTU"],"url":"http://ubuntu.com/usn/usn-667-1"},{"name":"31747","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/31747"},{"tags":["x_refsource_MISC"],"url":"http://liudieyu0.blog124.fc2.com/blog-entry-6.html"},{"name":"32714","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/32714"},{"name":"31611","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/31611"},{"name":"34501","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/34501"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2008-4582","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Mozilla Firefox 3.0.1 through 3.0.3, Firefox 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13, when running on Windows, do not properly identify the context of Windows .url shortcut files, which allows user-assisted remote attackers to bypass the Same Origin Policy and obtain sensitive information via an HTML document that is directly accessible through a filesystem, as demonstrated by documents in (1) local folders, (2) Windows share folders, and (3) RAR archives, and as demonstrated by IFRAMEs referencing shortcuts that point to (a) about:cache?device=memory and (b) about:cache?device=disk, a variant of CVE-2008-2810."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"firefox-internet-shortcut-info-disclosure(45740)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/45740"},{"name":"DSA-1697","refsource":"DEBIAN","url":"http://www.debian.org/security/2009/dsa-1697"},{"name":"1021190","refsource":"SECTRACK","url":"http://www.securitytracker.com/id?1021190"},{"name":"DSA-1671","refsource":"DEBIAN","url":"http://www.debian.org/security/2008/dsa-1671"},{"name":"FEDORA-2008-9667","refsource":"FEDORA","url":"https://www.redhat.com/archives/fedora-package-announce/2008-November/msg00366.html"},{"name":"ADV-2009-0977","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2009/0977"},{"name":"https://bugzilla.mozilla.org/show_bug.cgi?id=455311","refsource":"MISC","url":"https://bugzilla.mozilla.org/show_bug.cgi?id=455311"},{"name":"32192","refsource":"SECUNIA","url":"http://secunia.com/advisories/32192"},{"name":"http://www.mozilla.org/security/announce/2008/mfsa2008-47.html","refsource":"CONFIRM","url":"http://www.mozilla.org/security/announce/2008/mfsa2008-47.html"},{"name":"1021212","refsource":"SECTRACK","url":"http://securitytracker.com/alerts/2008/Nov/1021212.html"},{"name":"DSA-1669","refsource":"DEBIAN","url":"http://www.debian.org/security/2008/dsa-1669"},{"name":"32778","refsource":"SECUNIA","url":"http://secunia.com/advisories/32778"},{"name":"FEDORA-2008-9669","refsource":"FEDORA","url":"https://www.redhat.com/archives/fedora-package-announce/2008-November/msg00385.html"},{"name":"33433","refsource":"SECUNIA","url":"http://secunia.com/advisories/33433"},{"name":"ADV-2008-2818","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2008/2818"},{"name":"20081007 Firefox Privacy Broken If Used to Open Web Page File","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/497091/100/0/threaded"},{"name":"256408","refsource":"SUNALERT","url":"http://sunsolve.sun.com/search/document.do?assetkey=1-26-256408-1"},{"name":"4416","refsource":"SREASON","url":"http://securityreason.com/securityalert/4416"},{"name":"32721","refsource":"SECUNIA","url":"http://secunia.com/advisories/32721"},{"name":"TA08-319A","refsource":"CERT","url":"http://www.us-cert.gov/cas/techalerts/TA08-319A.html"},{"name":"32853","refsource":"SECUNIA","url":"http://secunia.com/advisories/32853"},{"name":"DSA-1696","refsource":"DEBIAN","url":"http://www.debian.org/security/2009/dsa-1696"},{"name":"32693","refsource":"SECUNIA","url":"http://secunia.com/advisories/32693"},{"name":"32845","refsource":"SECUNIA","url":"http://secunia.com/advisories/32845"},{"name":"33434","refsource":"SECUNIA","url":"http://secunia.com/advisories/33434"},{"name":"32684","refsource":"SECUNIA","url":"http://secunia.com/advisories/32684"},{"name":"USN-667-1","refsource":"UBUNTU","url":"http://ubuntu.com/usn/usn-667-1"},{"name":"31747","refsource":"BID","url":"http://www.securityfocus.com/bid/31747"},{"name":"http://liudieyu0.blog124.fc2.com/blog-entry-6.html","refsource":"MISC","url":"http://liudieyu0.blog124.fc2.com/blog-entry-6.html"},{"name":"32714","refsource":"SECUNIA","url":"http://secunia.com/advisories/32714"},{"name":"31611","refsource":"BID","url":"http://www.securityfocus.com/bid/31611"},{"name":"34501","refsource":"SECUNIA","url":"http://secunia.com/advisories/34501"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2008-4582","datePublished":"2008-10-15T20:00:00.000Z","dateReserved":"2008-10-15T00:00:00.000Z","dateUpdated":"2024-08-07T10:24:19.339Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2008-10-15 20:08:02","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-264","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:N/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:debian:debian_linux:4.0:*:*:*:*:*:*:*","matchCriteriaId":"0F92AB32-E7DE-43F4-B877-1F41FA162EC7"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:firefox:3.0.1:*:*:*:*:*:*:*","matchCriteriaId":"11E07FED-ABDB-4B0A-AB2E-4CBF1EAC4301"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:firefox:3.0.2:*:*:*:*:*:*:*","matchCriteriaId":"9A6558F1-9E0D-4107-909A-8EF4BC8A9C2F"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:firefox:3.0.3:*:*:*:*:*:*:*","matchCriteriaId":"63DF3D65-C992-44CF-89B4-893526C6242E"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*","matchCriteriaId":"2CF61F35-5905-4BA9-AD7E-7DB261D2F256"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:firefox:2.0:*:*:*:*:*:*:*","matchCriteriaId":"3487FA64-BE04-42CA-861E-3DAC097D7D32"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:firefox:2.0.0.1:*:*:*:*:*:*:*","matchCriteriaId":"F3D956DC-C73B-439F-8D79-8239207CC76F"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:firefox:2.0.0.10:*:*:*:*:*:*:*","matchCriteriaId":"612B015E-9F96-4CE6-83E4-23848FD609E5"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:firefox:2.0.0.11:*:*:*:*:*:*:*","matchCriteriaId":"1E391619-0967-43E1-8CBC-4D54F72A85C2"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:firefox:2.0.0.12:*:*:*:*:*:*:*","matchCriteriaId":"0544D626-E269-4677-9B05-7DAB23BD103B"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:firefox:2.0.0.13:*:*:*:*:*:*:*","matchCriteriaId":"C95F7B2C-80FC-4DF2-9680-F74634DCE3E6"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:firefox:2.0.0.14:*:*:*:*:*:*:*","matchCriteriaId":"863C140E-DC15-4A88-AB8A-8AEF9F4B8164"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:firefox:2.0.0.15:*:*:*:*:*:*:*","matchCriteriaId":"38CD049A-5333-4FF7-AD34-6B74E19BADCB"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:firefox:2.0.0.16:*:*:*:*:*:*:*","matchCriteriaId":"0066576D-D66A-4B59-B5C3-471EEBEE8B9A"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:firefox:2.0.0.17:*:*:*:*:*:*:*","matchCriteriaId":"60ED6DAA-9194-4829-BC1A-00F04BE7930A"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*","matchCriteriaId":"2CF61F35-5905-4BA9-AD7E-7DB261D2F256"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:canonical:ubuntu_linux:6.06:*:*:*:lts:*:*:*","matchCriteriaId":"5C18C3CD-969B-4AA3-AE3A-BA4A188F8BFF"},{"vulnerable":true,"criteria":"cpe:2.3:o:canonical:ubuntu_linux:7.10:*:*:*:*:*:*:*","matchCriteriaId":"823BF8BE-2309-4F67-A5E2-EAD98F723468"},{"vulnerable":true,"criteria":"cpe:2.3:o:canonical:ubuntu_linux:8.04:*:*:*:lts:*:*:*","matchCriteriaId":"C91D2DBF-6DA7-4BA2-9F29-8BD2725A4701"},{"vulnerable":true,"criteria":"cpe:2.3:o:canonical:ubuntu_linux:8.10:*:*:*:*:*:*:*","matchCriteriaId":"4747CC68-FAF4-482F-929A-9DA6C24CB663"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:seamonkey:1.0:*:*:*:*:*:*:*","matchCriteriaId":"09E18FC0-0C8C-4FA1-85B9-B868D00F002F"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:seamonkey:1.0:alpha:*:*:*:*:*:*","matchCriteriaId":"4A97B6E1-EABA-4977-A3FC-64DF0392AA95"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:seamonkey:1.0:beta:*:*:*:*:*:*","matchCriteriaId":"CB01A97F-ACE1-4A99-8939-6DF8FE5B5E8E"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:seamonkey:1.0.1:*:*:*:*:*:*:*","matchCriteriaId":"6521C877-63C9-4B6E-9FC9-1263FFBB7950"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:seamonkey:1.0.2:*:*:*:*:*:*:*","matchCriteriaId":"D949DF0A-CBC2-40E1-AE6C-60E6F58D2481"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:seamonkey:1.0.3:*:*:*:*:*:*:*","matchCriteriaId":"3C5CDA57-1A50-4EDB-80E2-D3EBB44EA653"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:seamonkey:1.0.4:*:*:*:*:*:*:*","matchCriteriaId":"22D33486-4956-4E2C-BA16-FA269A9D02BD"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:seamonkey:1.0.5:*:*:*:*:*:*:*","matchCriteriaId":"3104343E-93B6-4D4A-BC95-ED9F7E91FB6A"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:seamonkey:1.0.6:*:*:*:*:*:*:*","matchCriteriaId":"381313EF-DF84-4F66-9962-DE8F45029D79"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:seamonkey:1.0.7:*:*:*:*:*:*:*","matchCriteriaId":"A0228476-14E4-443C-BBAE-2C9CD8594DC0"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:seamonkey:1.0.8:*:*:*:*:*:*:*","matchCriteriaId":"A803A500-DCE2-44FC-ABEB-A90A1D39D85C"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:seamonkey:1.0.9:*:*:*:*:*:*:*","matchCriteriaId":"022274DE-5251-49C9-B6E5-1D8CEDC34E7D"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:seamonkey:1.1:*:*:*:*:*:*:*","matchCriteriaId":"B9F84CB7-93F7-4912-BC87-497867B96491"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:seamonkey:1.1:alpha:*:*:*:*:*:*","matchCriteriaId":"8992E9C6-09B3-492E-B7DA-899D5238EC18"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:seamonkey:1.1:beta:*:*:*:*:*:*","matchCriteriaId":"D58B704B-F06E-44C1-BBD1-A090D1E6583A"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:seamonkey:1.1.1:*:*:*:*:*:*:*","matchCriteriaId":"40270FBD-744A-49D9-9FFA-1DCD897210D7"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:seamonkey:1.1.2:*:*:*:*:*:*:*","matchCriteriaId":"20E01097-F60A-4FB2-BA47-84A267EE87D6"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:seamonkey:1.1.3:*:*:*:*:*:*:*","matchCriteriaId":"7F65732F-317B-49A2-B9B0-FA1102B8B45C"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:seamonkey:1.1.4:*:*:*:*:*:*:*","matchCriteriaId":"DB430F19-069A-43FD-9097-586D4449D327"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:seamonkey:1.1.5:*:*:*:*:*:*:*","matchCriteriaId":"76AD0439-3BFB-4AD1-8E2C-99D0B099FA8C"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:seamonkey:1.1.6:*:*:*:*:*:*:*","matchCriteriaId":"1E6D7528-E591-48A6-8165-BE42F8EBF6B6"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:seamonkey:1.1.7:*:*:*:*:*:*:*","matchCriteriaId":"BA710423-0075-44B8-9DCB-6380FA974486"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:seamonkey:1.1.8:*:*:*:*:*:*:*","matchCriteriaId":"C5521DA3-E6AF-4350-B971-10B4A1C9B1D1"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:seamonkey:1.1.9:*:*:*:*:*:*:*","matchCriteriaId":"DDD15752-A253-47B1-BCE0-B55B84B47C9F"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:seamonkey:1.1.10:*:*:*:*:*:*:*","matchCriteriaId":"60B39A9D-44A4-4D7F-9004-C44066BBE277"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:seamonkey:1.1.11:*:*:*:*:*:*:*","matchCriteriaId":"F203EC52-2126-4227-AF3B-23857E5BB222"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:seamonkey:1.1.12:*:*:*:*:*:*:*","matchCriteriaId":"E951567B-8402-42EA-AE33-EBA9235A868F"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*","matchCriteriaId":"2CF61F35-5905-4BA9-AD7E-7DB261D2F256"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2008","CveId":"4582","Ordinal":"1","Title":"CVE-2008-4582","CVE":"CVE-2008-4582","Year":"2008"},"notes":[{"CveYear":"2008","CveId":"4582","Ordinal":"1","NoteData":"Mozilla Firefox 3.0.1 through 3.0.3, Firefox 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13, when running on Windows, do not properly identify the context of Windows .url shortcut files, which allows user-assisted remote attackers to bypass the Same Origin Policy and obtain sensitive information via an HTML document that is directly accessible through a filesystem, as demonstrated by documents in (1) local folders, (2) Windows share folders, and (3) RAR archives, and as demonstrated by IFRAMEs referencing shortcuts that point to (a) about:cache?device=memory and (b) about:cache?device=disk, a variant of CVE-2008-2810.","Type":"Description","Title":"CVE-2008-4582"},{"CveYear":"2008","CveId":"4582","Ordinal":"2","NoteData":"2008-10-15","Type":"Other","Title":"Published"},{"CveYear":"2008","CveId":"4582","Ordinal":"3","NoteData":"2018-10-11","Type":"Other","Title":"Modified"}]}}}