CVE-2008-4062

CVSS v2.0 10 (High)
100% Progress
EPSS 2.83 % (91th)
2.83% Progress
Affected Products 5
Advisories 12

Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the JavaScript engine and (1) misinterpretation of the characteristics of Namespace and QName in jsxml.c, (2) misuse of signed integers in the nsEscapeCount function in nsEscape.cpp, and (3) interaction of JavaScript garbage collection with certain use of an NPObject in the nsNPObjWrapper::GetNewOrUsed function in nsJSNPRuntime.cpp.

Weaknesses
CWE-399
Resource Management Errors
CWE-NVD-noinfo
CVE Status
PUBLISHED
CNA
Red Hat, Inc.
Published Date
2008-09-24 20:37:04
(16 years ago)
Updated Date
2018-11-01 16:23:06
(5 years ago)

Affected Products

Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Mozilla Firefox prior 2.0.0.17 version cpe:2.3:a:mozilla:firefox < 2.0.0.17
  Mozilla Firefox from 3.0 version and prior 3.0.2 version cpe:2.3:a:mozilla:firefox >= 3.0 < 3.0.2
  Mozilla Seamonkey prior 1.1.12 version cpe:2.3:a:mozilla:seamonkey < 1.1.12
  Mozilla Thunderbird prior 2.0.0.17 version cpe:2.3:a:mozilla:thunderbird < 2.0.0.17

Configuration #2

    CPE23 From Up To
  Debian Linux 4.0 cpe:2.3:o:debian:debian_linux:4.0

Configuration #3

    CPE23 From Up To
  Canonical Ubuntu Linux 6.06 cpe:2.3:o:canonical:ubuntu_linux:6.06:*:*:*:lts
  Canonical Ubuntu Linux 7.04 cpe:2.3:o:canonical:ubuntu_linux:7.04
  Canonical Ubuntu Linux 7.10 cpe:2.3:o:canonical:ubuntu_linux:7.10
  Canonical Ubuntu Linux 8.04 cpe:2.3:o:canonical:ubuntu_linux:8.04:*:*:*:lts
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...