Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).
CVE-2008-2419 — Mozilla Firefox vulnerability
Severity
4.3MEDIUMNVD
EPSS
11.7%
top 6.30%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedMay 23
Latest updateMay 1
Description
Mozilla Firefox 2.0.0.14 allows remote attackers to cause a denial of service (heap corruption and application crash) or possibly execute arbitrary code by triggering an error condition during certain Iframe operations between a JSframe write and a JSframe close, as demonstrated by an error in loading an empty Java applet defined by a 'src="javascript:"' sequence.
CVSS vector
AV:N/AC:M/C:N/I:N/A:PExploitability: 8.6 | Impact: 2.9
Affected Packages1 packages
🔴Vulnerability Details
1💥Exploits & PoCs
1📋Vendor Advisories
1Red Hat▶
firefox: heap corruption during Iframe operations between a JSframe write and a JSframe close↗2008-05-21
💬Community
1Bugzilla▶
CVE-2008-2419 firefox: heap corruption during Iframe operations between a JSframe write and a JSframe close↗2008-05-26