CVE-2008-5052
Last modified
CVE-2008-5052 is a vulnerability of currently unknown severity. The AppendAttributeValue function in the JavaScript engine in Mozilla Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) via unknown vectors that trigger memory corruption, as demonstrated by e4x/extensions/regress-410192.js.. EPSS estimates a 3.48% chance of exploitation in the next 30 days.
Description
The AppendAttributeValue function in the JavaScript engine in Mozilla Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) via unknown vectors that trigger memory corruption, as demonstrated by e4x/extensions/regress-410192.js.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox | >= 2.0, < 2.0.0.18 |
| Mozilla | Seamonkey | >= 1.0, <= 1.1.13 |
| Mozilla | Thunderbird | >= 2.0, < 2.0.0.18 |
References
- http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00004.htmlThird Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:228Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:235Third Party Advisory
- http://www.securityfocus.com/bid/32281Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1021183Third Party Advisory, VDB Entry
- http://www.us-cert.gov/cas/techalerts/TA08-319A.htmlThird Party Advisory, US Government Resource
- http://www.vupen.com/english/advisories/2008/3146Third Party Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=454113Issue Tracking, Vendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00004.htmlThird Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:228Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:235Third Party Advisory
- http://www.securityfocus.com/bid/32281Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1021183Third Party Advisory, VDB Entry
- http://www.us-cert.gov/cas/techalerts/TA08-319A.htmlThird Party Advisory, US Government Resource
- http://www.vupen.com/english/advisories/2008/3146Third Party Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=454113Issue Tracking, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-5052?
How severe is CVE-2008-5052?
How do I fix CVE-2008-5052?
Are you affected by CVE-2008-5052?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
