CVE-2008-5016Reachable Assertion in Mozilla Firefox

CWE-3997 documents6 sources
Severity
5.0MEDIUMNVD
EPSS
21.3%
top 4.31%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 13
Latest updateMay 17

Description

The layout engine in Mozilla Firefox 3.x before 3.0.4, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) via multiple vectors that trigger an assertion failure or other consequences.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages3 packages

NVDmozilla/firefox3.0.3+3
NVDmozilla/seamonkey1.1.12+22
NVDmozilla/thunderbird2.0.0.17+7

🔴Vulnerability Details

2
GHSA
GHSA-9gm5-4h53-36xh: The layout engine in Mozilla Firefox 32022-05-17
CVEList
CVE-2008-5016: The layout engine in Mozilla Firefox 32008-11-13

📋Vendor Advisories

3
Ubuntu
Thunderbird vulnerabilities2008-11-26
Ubuntu
Firefox and xulrunner vulnerabilities2008-11-17
Red Hat
Mozilla crash with evidence of memory corruption2008-11-12

💬Community

1
Bugzilla
CVE-2008-5016 Mozilla crash with evidence of memory corruption2008-11-10
CVE-2008-5016 — Reachable Assertion in Mozilla Firefox | cvebase