CVE-2008-5052Out-of-bounds Write in Mozilla Firefox

CWE-3995 documents5 sources
Severity
10.0CRITICALNVD
EPSS
18.7%
top 4.72%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 13
Latest updateMay 14

Description

The AppendAttributeValue function in the JavaScript engine in Mozilla Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) via unknown vectors that trigger memory corruption, as demonstrated by e4x/extensions/regress-410192.js.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages3 packages

NVDmozilla/firefox2.02.0.0.18
NVDmozilla/thunderbird2.02.0.0.18
NVDmozilla/seamonkey1.01.1.13

🔴Vulnerability Details

2
GHSA
GHSA-4fmr-pw88-x9j3: The AppendAttributeValue function in the JavaScript engine in Mozilla Firefox 22022-05-14
CVEList
CVE-2008-5052: The AppendAttributeValue function in the JavaScript engine in Mozilla Firefox 22008-11-13

📋Vendor Advisories

1
Red Hat
security flaw2008-11-12

💬Community

1
Bugzilla
CVE-2008-5052 security flaw2018-08-16
CVE-2008-5052 — Out-of-bounds Write in Mozilla Firefox | cvebase