PublicDate: 2008-07-17 13:41:00 UTC Candidate: CVE-2008-3198 References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3198 Description: Mozilla Firefox 3.x before 3.0.1 allows remote attackers to inject arbitrary web script into a chrome document via unspecified vectors, as demonstrated by injection into a XUL error page. NOTE: this can be leveraged to execute arbitrary code using CVE-2008-2933. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: Patches_firefox-3.0: upstream_firefox-3.0: released (3.0.1) dapper_firefox-3.0: DNE feisty_firefox-3.0: DNE gutsy_firefox-3.0: needed (reached end-of-life) hardy_firefox-3.0: not-affected intrepid_firefox-3.0: not-affected devel_firefox-3.0: not-affected