CVE-2008-1380
published 2008-04-17CVE-2008-1380: The JavaScript engine in Mozilla Firefox before 2.0.0.14, Thunderbird before 2.0.0.14, and SeaMonkey before 1.1.10 allows remote attackers to cause a denial of…
PriorityP427critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
2.90%
85.4th percentile
The JavaScript engine in Mozilla Firefox before 2.0.0.14, Thunderbird before 2.0.0.14, and SeaMonkey before 1.1.10 allows remote attackers to cause a denial of service (garbage collector crash) and possibly have other impacts via a crafted web page. NOTE: this is due to an incorrect fix for CVE-2008-1237.
Affected
46 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 2.0.0.13 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | seamonkey | <= 1.1.9 | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_ubuntu9.3CRITICAL
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2008-04-22·CVSS 9.3
CVE-2008-1380 [CRITICAL] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox vulnerabilities
Flaws were discovered in Firefox which could lead to crashes during
JavaScript garbage collection. If a user were tricked into opening a
malicious web page, an attacker may be able to crash the browser or
possibly execute arbitrary code with the user's privileges.
(CVE-2008-1380)
Instructions: After a standard system upgrade you need to restart firefox to effect
the necessary changes.
Red Hat
Firefox JavaScript garbage collection crash
vendor_redhat·2008-04-16·CVSS 6.8
CVE-2008-1380 [MEDIUM] Firefox JavaScript garbage collection crash
Firefox JavaScript garbage collection crash
The JavaScript engine in Mozilla Firefox before 2.0.0.14, Thunderbird before 2.0.0.14, and SeaMonkey before 1.1.10 allows remote attackers to cause a denial of service (garbage collector crash) and possibly have other impacts via a crafted web page. NOTE: this is due to an incorrect fix for CVE-2008-1237.
GHSA
GHSA-q7cx-jxvc-hrmp: The JavaScript engine in Mozilla Firefox before 2
ghsa_unreviewed·2022-05-01·CVSS 6.8
CVE-2008-1380 [MEDIUM] GHSA-q7cx-jxvc-hrmp: The JavaScript engine in Mozilla Firefox before 2
The JavaScript engine in Mozilla Firefox before 2.0.0.14, Thunderbird before 2.0.0.14, and SeaMonkey before 1.1.10 allows remote attackers to cause a denial of service (garbage collector crash) and possibly have other impacts via a crafted web page. NOTE: this is due to an incorrect fix for CVE-2008-1237.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2008-05/msg00000.htmlhttp://secunia.com/advisories/29787http://secunia.com/advisories/29793http://secunia.com/advisories/29828http://secunia.com/advisories/29860http://secunia.com/advisories/29883http://secunia.com/advisories/29908http://secunia.com/advisories/29911http://secunia.com/advisories/29912http://secunia.com/advisories/29947http://secunia.com/advisories/30012http://secunia.com/advisories/30029http://secunia.com/advisories/30192http://secunia.com/advisories/30327http://secunia.com/advisories/30620http://secunia.com/advisories/30717http://secunia.com/advisories/31023http://secunia.com/advisories/31377http://secunia.com/advisories/33434http://security.gentoo.org/glsa/glsa-200808-03.xmlhttp://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.383152http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.391769http://sunsolve.sun.com/search/document.do?assetkey=1-26-238492-1http://www.debian.org/security/2008/dsa-1555http://www.debian.org/security/2008/dsa-1558http://www.debian.org/security/2008/dsa-1562http://www.debian.org/security/2009/dsa-1696http://www.gentoo.org/security/en/glsa/glsa-200805-18.xmlhttp://www.kb.cert.org/vuls/id/441529http://www.mandriva.com/security/advisories?name=MDVSA-2008:110http://www.mozilla.org/security/announce/2008/mfsa2008-20.htmlhttp://www.novell.com/linux/security/advisories/2008_13_sr.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0222.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0223.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0224.htmlhttp://www.securityfocus.com/archive/1/491838/100/0/threadedhttp://www.securityfocus.com/bid/28818http://www.securitytracker.com/id?1019873http://www.ubuntu.com/usn/usn-602-1http://www.vupen.com/english/advisories/2008/1251/referenceshttp://www.vupen.com/english/advisories/2008/1793/referenceshttps://bugzilla.mozilla.org/show_bug.cgi?id=425576https://exchange.xforce.ibmcloud.com/vulnerabilities/41857https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10752https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00407.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-April/msg00463.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-May/msg00058.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-May/msg00074.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-05/msg00000.htmlhttp://secunia.com/advisories/29787http://secunia.com/advisories/29793http://secunia.com/advisories/29828http://secunia.com/advisories/29860http://secunia.com/advisories/29883http://secunia.com/advisories/29908http://secunia.com/advisories/29911http://secunia.com/advisories/29912http://secunia.com/advisories/29947http://secunia.com/advisories/30012http://secunia.com/advisories/30029http://secunia.com/advisories/30192http://secunia.com/advisories/30327http://secunia.com/advisories/30620http://secunia.com/advisories/30717http://secunia.com/advisories/31023http://secunia.com/advisories/31377http://secunia.com/advisories/33434http://security.gentoo.org/glsa/glsa-200808-03.xmlhttp://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.383152http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.391769http://sunsolve.sun.com/search/document.do?assetkey=1-26-238492-1http://www.debian.org/security/2008/dsa-1555http://www.debian.org/security/2008/dsa-1558http://www.debian.org/security/2008/dsa-1562http://www.debian.org/security/2009/dsa-1696http://www.gentoo.org/security/en/glsa/glsa-200805-18.xmlhttp://www.kb.cert.org/vuls/id/441529http://www.mandriva.com/security/advisories?name=MDVSA-2008:110http://www.mozilla.org/security/announce/2008/mfsa2008-20.htmlhttp://www.novell.com/linux/security/advisories/2008_13_sr.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0222.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0223.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0224.htmlhttp://www.securityfocus.com/archive/1/491838/100/0/threadedhttp://www.securityfocus.com/bid/28818http://www.securitytracker.com/id?1019873http://www.ubuntu.com/usn/usn-602-1http://www.vupen.com/english/advisories/2008/1251/referenceshttp://www.vupen.com/english/advisories/2008/1793/referenceshttps://bugzilla.mozilla.org/show_bug.cgi?id=425576https://exchange.xforce.ibmcloud.com/vulnerabilities/41857https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10752https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00407.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-April/msg00463.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-May/msg00058.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-May/msg00074.html
2008-04-17
Published