CVE-2008-4063
published 2008-09-24CVE-2008-4063: Multiple unspecified vulnerabilities in Mozilla Firefox 3.x before 3.0.2 allow remote attackers to cause a denial of service (memory corruption and application…
PriorityP434critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
3.96%
89.4th percentile
Multiple unspecified vulnerabilities in Mozilla Firefox 3.x before 3.0.2 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the layout engine and (1) a zero value of the "this" variable in the nsContentList::Item function; (2) interaction of the indic IME extension, a Hindi language selection, and the "g" character; and (3) interaction of the nsFrameList::SortByContentOrder function with a certain insufficient protection of inline frames.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| mozilla | firefox | <= 3.0.1 | — |
| mozilla | firefox | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_ubuntu10.0CRITICAL
vendor_redhat9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2008-09-26·CVSS 7.5
CVE-2008-4067 [HIGH] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Thunderbird vulnerabilities
It was discovered that the same-origin check in Thunderbird could
be bypassed. If a user had JavaScript enabled and were tricked into
opening a malicious website, an attacker may be able to execute
JavaScript in the context of a different website. (CVE-2008-3835)
Several problems were discovered in the browser engine of
Thunderbird. If a user had JavaScript enabled, this could allow an
attacker to execute code with chrome privileges. (CVE-2008-4058,
CVE-2008-4059, CVE-2008-4060)
Drew Yao, David Maciejak and other Mozilla developers found several
problems in the browser engine of Thunderbird. If a user had
JavaScript enabled and were tricked into opening a malicious web
page, an attacker could cause a denial of serv
Ubuntu
Firefox and xulrunner regression
vendor_ubuntu·2008-09-25·CVSS 10.0
[CRITICAL] Firefox and xulrunner regression
Title: Firefox and xulrunner regression
Summary: Firefox and xulrunner regression
USN-645-1 fixed vulnerabilities in Firefox and xulrunner. The upstream
patches introduced a regression in the saved password handling. While
password data was not lost, if a user had saved any passwords with
non-ASCII characters, Firefox could not access the password database.
This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Justin Schuh, Tom Cross and Peter Williams discovered errors in the
Firefox URL parsing routines. If a user were tricked into opening a
crafted hyperlink, an attacker could overflow a stack buffer and
execute arbitrary code. (CVE-2008-0016)
It was discovered that the same-origin check in Firefox could be
bypassed. If a user were tricked i
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2008-09-24·CVSS 10.0
CVE-2008-0016 [CRITICAL] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox vulnerabilities
USN-645-1 fixed vulnerabilities in Firefox and xulrunner for Ubuntu
7.04, 7.10 and 8.04 LTS. This provides the corresponding update for
Ubuntu 6.06 LTS.
Original advisory details:
Justin Schuh, Tom Cross and Peter Williams discovered errors in the
Firefox URL parsing routines. If a user were tricked into opening a
crafted hyperlink, an attacker could overflow a stack buffer and
execute arbitrary code. (CVE-2008-0016)
It was discovered that the same-origin check in Firefox could be
bypassed. If a user were tricked into opening a malicious website,
an attacker may be able to execute JavaScript in the context of a
different website. (CVE-2008-3835)
Several problems were discovered in the JavaScript engine. This
could allow
Ubuntu
Firefox and xulrunner vulnerabilities
vendor_ubuntu·2008-09-24·CVSS 10.0
CVE-2008-0016 [CRITICAL] Firefox and xulrunner vulnerabilities
Title: Firefox and xulrunner vulnerabilities
Summary: Firefox and xulrunner vulnerabilities
Justin Schuh, Tom Cross and Peter Williams discovered errors in the
Firefox URL parsing routines. If a user were tricked into opening a
crafted hyperlink, an attacker could overflow a stack buffer and
execute arbitrary code. (CVE-2008-0016)
It was discovered that the same-origin check in Firefox could be
bypassed. If a user were tricked into opening a malicious website,
an attacker may be able to execute JavaScript in the context of a
different website. (CVE-2008-3835)
Several problems were discovered in the JavaScript engine. This
could allow an attacker to execute scripts from page content with
chrome privileges. (CVE-2008-3836)
Paul Nickerson discovered Firefox did not properly process mouse
Red Hat
Mozilla crashes with evidence of memory corruption
vendor_redhat·2008-09-23·CVSS 9.3
CVE-2008-4063 [CRITICAL] Mozilla crashes with evidence of memory corruption
Mozilla crashes with evidence of memory corruption
Multiple unspecified vulnerabilities in Mozilla Firefox 3.x before 3.0.2 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the layout engine and (1) a zero value of the "this" variable in the nsContentList::Item function; (2) interaction of the indic IME extension, a Hindi language selection, and the "g" character; and (3) interaction of the nsFrameList::SortByContentOrder function with a certain insufficient protection of inline frames.
GHSA
GHSA-jrcw-h5xr-875m: Multiple unspecified vulnerabilities in Mozilla Firefox 3
ghsa_unreviewed·2022-05-02
CVE-2008-4063 [HIGH] GHSA-jrcw-h5xr-875m: Multiple unspecified vulnerabilities in Mozilla Firefox 3
Multiple unspecified vulnerabilities in Mozilla Firefox 3.x before 3.0.2 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the layout engine and (1) a zero value of the "this" variable in the nsContentList::Item function; (2) interaction of the indic IME extension, a Hindi language selection, and the "g" character; and (3) interaction of the nsFrameList::SortByContentOrder function with a certain insufficient protection of inline frames.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2008-10/msg00005.htmlhttp://secunia.com/advisories/31987http://secunia.com/advisories/32011http://secunia.com/advisories/32012http://secunia.com/advisories/32025http://secunia.com/advisories/32044http://secunia.com/advisories/32082http://secunia.com/advisories/32089http://secunia.com/advisories/32095http://secunia.com/advisories/32096http://secunia.com/advisories/32196http://secunia.com/advisories/34501http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.379422http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.412123http://sunsolve.sun.com/search/document.do?assetkey=1-26-256408-1http://www.mozilla.org/security/announce/2008/mfsa2008-42.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0879.htmlhttp://www.securityfocus.com/bid/31346http://www.securitytracker.com/id?1020916http://www.ubuntu.com/usn/usn-645-1http://www.ubuntu.com/usn/usn-645-2http://www.ubuntu.com/usn/usn-647-1http://www.vupen.com/english/advisories/2008/2661http://www.vupen.com/english/advisories/2009/0977https://bugzilla.mozilla.org/show_bug.cgi?id=413048https://bugzilla.mozilla.org/show_bug.cgi?id=433758https://bugzilla.mozilla.org/show_bug.cgi?id=444452https://exchange.xforce.ibmcloud.com/vulnerabilities/45354https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11151https://www.redhat.com/archives/fedora-package-announce/2008-September/msg01335.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-10/msg00005.htmlhttp://secunia.com/advisories/31987http://secunia.com/advisories/32011http://secunia.com/advisories/32012http://secunia.com/advisories/32025http://secunia.com/advisories/32044http://secunia.com/advisories/32082http://secunia.com/advisories/32089http://secunia.com/advisories/32095http://secunia.com/advisories/32096http://secunia.com/advisories/32196http://secunia.com/advisories/34501http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.379422http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.412123http://sunsolve.sun.com/search/document.do?assetkey=1-26-256408-1http://www.mozilla.org/security/announce/2008/mfsa2008-42.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0879.htmlhttp://www.securityfocus.com/bid/31346http://www.securitytracker.com/id?1020916http://www.ubuntu.com/usn/usn-645-1http://www.ubuntu.com/usn/usn-645-2http://www.ubuntu.com/usn/usn-647-1http://www.vupen.com/english/advisories/2008/2661http://www.vupen.com/english/advisories/2009/0977https://bugzilla.mozilla.org/show_bug.cgi?id=413048https://bugzilla.mozilla.org/show_bug.cgi?id=433758https://bugzilla.mozilla.org/show_bug.cgi?id=444452https://exchange.xforce.ibmcloud.com/vulnerabilities/45354https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11151https://www.redhat.com/archives/fedora-package-announce/2008-September/msg01335.html
2008-09-24
Published