CVE-2008-5014Improper Input Validation in Mozilla Firefox

Severity
10.0CRITICALNVD
EPSS
25.2%
top 3.80%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 13
Latest updateMay 14

Description

jslock.cpp in Mozilla Firefox 3.x before 3.0.2, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by modifying the window.__proto__.__proto__ object in a way that causes a lock on a non-native object, which triggers an assertion failure related to the OBJ_IS_NATIVE function.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages3 packages

NVDmozilla/firefox2.02.0.0.18+1
NVDmozilla/seamonkey1.01.1.13
NVDmozilla/thunderbird2.02.0.0.18

Also affects: Debian Linux 4.0, Ubuntu Linux 6.06, 7.10, 8.04, 8.10

🔴Vulnerability Details

2
GHSA
GHSA-8m88-6wvj-46c6: jslock2022-05-14
CVEList
CVE-2008-5014: jslock2008-11-13

📋Vendor Advisories

3
Ubuntu
Thunderbird vulnerabilities2008-11-26
Ubuntu
Firefox and xulrunner vulnerabilities2008-11-17
Red Hat
Mozilla crash and remote code execution via __proto__ tampering2008-11-12

💬Community

1
Bugzilla
CVE-2008-5014 Mozilla crash and remote code execution via __proto__ tampering2008-11-10
CVE-2008-5014 — Improper Input Validation in Mozilla | cvebase