CVE-2008-5502Out-of-bounds Write in Mozilla Firefox

CWE-3996 documents6 sources
Severity
5.0MEDIUMNVD
EPSS
3.8%
top 11.94%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 17
Latest updateMay 14

Description

The layout engine in Mozilla Firefox 3.x before 3.0.5, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to cause a denial of service (crash) via vectors that trigger memory corruption, related to the GetXMLEntity and FastAppendChar functions.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages2 packages

NVDmozilla/firefox2.02.0.0.19+1
NVDmozilla/seamonkey1.01.1.14

Also affects: Ubuntu Linux 8.04, 8.10

🔴Vulnerability Details

2
GHSA
GHSA-jfx6-pmj2-6ffh: The layout engine in Mozilla Firefox 32022-05-14
CVEList
CVE-2008-5502: The layout engine in Mozilla Firefox 32008-12-17

📋Vendor Advisories

2
Ubuntu
Firefox and xulrunner vulnerabilities2008-12-17
Red Hat
JavaScript engine crash - Firefox 3 only2008-12-16

💬Community

1
Bugzilla
CVE-2008-5502 JavaScript engine crash - Firefox 3 only2008-12-12
CVE-2008-5502 — Out-of-bounds Write in Mozilla Firefox | cvebase