CVE-2008-5502
published 2008-12-17CVE-2008-5502: The layout engine in Mozilla Firefox 3.x before 3.0.5, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to cause a…
PriorityP417medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
2.27%
81.3th percentile
The layout engine in Mozilla Firefox 3.x before 3.0.5, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to cause a denial of service (crash) via vectors that trigger memory corruption, related to the GetXMLEntity and FastAppendChar functions.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| mozilla | firefox | >= 2.0 < 2.0.0.19 | 2.0.0.19 |
| mozilla | firefox | >= 3.0 < 3.0.5 | 3.0.5 |
| mozilla | seamonkey | >= 1.0 < 1.1.14 | 1.1.14 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_ubuntu10.0CRITICAL
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Firefox and xulrunner vulnerabilities
vendor_ubuntu·2008-12-17·CVSS 10.0
CVE-2008-5502 [CRITICAL] Firefox and xulrunner vulnerabilities
Title: Firefox and xulrunner vulnerabilities
Summary: Firefox and xulrunner vulnerabilities
Several flaws were discovered in the browser engine. These problems could allow
an attacker to crash the browser and possibly execute arbitrary code with user
privileges. (CVE-2008-5500, CVE-2008-5501, CVE-2008-5502)
It was discovered that Firefox did not properly handle persistent cookie data.
If a user were tricked into opening a malicious website, an attacker could
write persistent data in the user's browser and track the user across browsing
sessions. (CVE-2008-5505)
Marius Schilder discovered that Firefox did not properly handle redirects to
an outside domain when an XMLHttpRequest was made to a same-origin resource.
It's possible that sensitive information could be revealed in the
XMLHttpR
Red Hat
JavaScript engine crash - Firefox 3 only
vendor_redhat·2008-12-16·CVSS 5.0
CVE-2008-5502 [MEDIUM] JavaScript engine crash - Firefox 3 only
JavaScript engine crash - Firefox 3 only
The layout engine in Mozilla Firefox 3.x before 3.0.5, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to cause a denial of service (crash) via vectors that trigger memory corruption, related to the GetXMLEntity and FastAppendChar functions.
GHSA
GHSA-jfx6-pmj2-6ffh: The layout engine in Mozilla Firefox 3
ghsa_unreviewed·2022-05-14
CVE-2008-5502 [MEDIUM] GHSA-jfx6-pmj2-6ffh: The layout engine in Mozilla Firefox 3
The layout engine in Mozilla Firefox 3.x before 3.0.5, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to cause a denial of service (crash) via vectors that trigger memory corruption, related to the GetXMLEntity and FastAppendChar functions.
No detection rules found.
No public exploits indexed.
http://secunia.com/advisories/33188http://secunia.com/advisories/33189http://secunia.com/advisories/33203http://secunia.com/advisories/33216http://secunia.com/advisories/33421http://secunia.com/advisories/34501http://sunsolve.sun.com/search/document.do?assetkey=1-26-256408-1http://www.mandriva.com/security/advisories?name=MDVSA-2008:245http://www.mozilla.org/security/announce/2008/mfsa2008-60.htmlhttp://www.redhat.com/support/errata/RHSA-2008-1036.htmlhttp://www.redhat.com/support/errata/RHSA-2008-1037.htmlhttp://www.redhat.com/support/errata/RHSA-2009-0002.htmlhttp://www.securityfocus.com/bid/32882http://www.securitytracker.com/id?1021417http://www.vupen.com/english/advisories/2009/0977https://bugzilla.mozilla.org/show_bug.cgi?id=458679https://exchange.xforce.ibmcloud.com/vulnerabilities/47408https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10001https://usn.ubuntu.com/690-1/http://secunia.com/advisories/33188http://secunia.com/advisories/33189http://secunia.com/advisories/33203http://secunia.com/advisories/33216http://secunia.com/advisories/33421http://secunia.com/advisories/34501http://sunsolve.sun.com/search/document.do?assetkey=1-26-256408-1http://www.mandriva.com/security/advisories?name=MDVSA-2008:245http://www.mozilla.org/security/announce/2008/mfsa2008-60.htmlhttp://www.redhat.com/support/errata/RHSA-2008-1036.htmlhttp://www.redhat.com/support/errata/RHSA-2008-1037.htmlhttp://www.redhat.com/support/errata/RHSA-2009-0002.htmlhttp://www.securityfocus.com/bid/32882http://www.securitytracker.com/id?1021417http://www.vupen.com/english/advisories/2009/0977https://bugzilla.mozilla.org/show_bug.cgi?id=458679https://exchange.xforce.ibmcloud.com/vulnerabilities/47408https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10001https://usn.ubuntu.com/690-1/
2008-12-17
Published