CVE-2008-5018Mozilla Firefox vulnerability

CWE-3997 documents6 sources
Severity
10.0CRITICALNVD
EPSS
20.2%
top 4.48%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 13
Latest updateMay 14

Description

The JavaScript engine in Mozilla Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) via vectors related to "insufficient class checking" in the Date class.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages3 packages

NVDmozilla/firefox2.02.0.0.18+1
NVDmozilla/seamonkey1.01.1.13
NVDmozilla/thunderbird2.02.0.0.18

Also affects: Debian Linux 4.0, Ubuntu Linux 6.06, 7.10, 8.04, 8.10

🔴Vulnerability Details

2
GHSA
GHSA-ww2m-xjhr-w96h: The JavaScript engine in Mozilla Firefox 32022-05-14
CVEList
CVE-2008-5018: The JavaScript engine in Mozilla Firefox 32008-11-13

📋Vendor Advisories

3
Ubuntu
Thunderbird vulnerabilities2008-11-26
Ubuntu
Firefox and xulrunner vulnerabilities2008-11-17
Red Hat
Mozilla crash with evidence of memory corruption2008-11-12

💬Community

1
Bugzilla
CVE-2008-5018 Mozilla crash with evidence of memory corruption2008-11-10
CVE-2008-5018 — Mozilla Firefox vulnerability | cvebase