PT-2008-2965 · Mozilla+1 · Firefox+3

Ryan Giobbi

·

Published

2008-04-17

·

Updated

2023-02-13

·

CVE-2008-1380

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Mozilla Firefox versions prior to 2.0.0.14 Thunderbird versions prior to 2.0.0.14 SeaMonkey versions prior to 1.1.10
Description The JavaScript engine in the affected software allows remote attackers to cause a denial of service, potentially leading to a garbage collector crash, via a crafted web page. This issue is a result of an incorrect fix.
Recommendations For Mozilla Firefox versions prior to 2.0.0.14, update to version 2.0.0.14 or later. For Thunderbird versions prior to 2.0.0.14, update to version 2.0.0.14 or later. For SeaMonkey versions prior to 1.1.10, update to version 1.1.10 or later.

Fix

DoS

Weakness Enumeration

Related Identifiers

CVE-2008-1380
DSA-1555-1
DSA-1558-1
DSA-1562-1
DSA-1696-1
RHSA-2008:0222
RHSA-2008:0223
RHSA-2008:0224
RHSA-2008_0222
RHSA-2008_0223
RHSA-2008_0224

Affected Products

Firefox
Red Hat
Seamonkey
Thunderbird