CVE-2008-5052
published 2008-11-13CVE-2008-5052: The AppendAttributeValue function in the JavaScript engine in Mozilla Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before…
PriorityP430critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
3.48%
87.9th percentile
The AppendAttributeValue function in the JavaScript engine in Mozilla Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) via unknown vectors that trigger memory corruption, as demonstrated by e4x/extensions/regress-410192.js.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | >= 2.0 < 2.0.0.18 | 2.0.0.18 |
| mozilla | seamonkey | 1.0 – 1.1.13 | — |
| mozilla | thunderbird | >= 2.0 < 2.0.0.18 | 2.0.0.18 |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4fmr-pw88-x9j3: The AppendAttributeValue function in the JavaScript engine in Mozilla Firefox 2
ghsa_unreviewed·2022-05-14
CVE-2008-5052 [HIGH] GHSA-4fmr-pw88-x9j3: The AppendAttributeValue function in the JavaScript engine in Mozilla Firefox 2
The AppendAttributeValue function in the JavaScript engine in Mozilla Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) via unknown vectors that trigger memory corruption, as demonstrated by e4x/extensions/regress-410192.js.
Red Hat
security flaw
vendor_redhat·2008-11-12·CVSS 10.0
CVE-2008-5052 [CRITICAL] security flaw
security flaw
The AppendAttributeValue function in the JavaScript engine in Mozilla Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) via unknown vectors that trigger memory corruption, as demonstrated by e4x/extensions/regress-410192.js.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00004.htmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2008:228http://www.mandriva.com/security/advisories?name=MDVSA-2008:235http://www.mozilla.org/security/announce/2008/mfsa2008-52.htmlhttp://www.securityfocus.com/bid/32281http://www.securitytracker.com/id?1021183http://www.us-cert.gov/cas/techalerts/TA08-319A.htmlhttp://www.vupen.com/english/advisories/2008/3146https://bugzilla.mozilla.org/show_bug.cgi?id=454113https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9449http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00004.htmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2008:228http://www.mandriva.com/security/advisories?name=MDVSA-2008:235http://www.mozilla.org/security/announce/2008/mfsa2008-52.htmlhttp://www.securityfocus.com/bid/32281http://www.securitytracker.com/id?1021183http://www.us-cert.gov/cas/techalerts/TA08-319A.htmlhttp://www.vupen.com/english/advisories/2008/3146https://bugzilla.mozilla.org/show_bug.cgi?id=454113https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9449
2008-11-13
Published