CVE Vulnerabilities

CVE-2008-2785

Published: Jun 19, 2008 | Modified: Oct 11, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

Mozilla Firefox before 2.0.0.16 and 3.x before 3.0.1, Thunderbird before 2.0.0.16, and SeaMonkey before 1.1.11 use an incorrect integer data type as a CSS object reference counter in the CSSValue array (aka nsCSSValue:Array) data structure, which allows remote attackers to execute arbitrary code via a large number of references to a common CSS object, leading to a counter overflow and a free of in-use memory, aka ZDI-CAN-349.

Affected Software

Name Vendor Start Version End Version
Firefox Mozilla * 2.0.0.15 (including)
Firefox Mozilla 2.0 (including) 2.0 (including)
Firefox Mozilla 2.0.0.1 (including) 2.0.0.1 (including)
Firefox Mozilla 2.0.0.2 (including) 2.0.0.2 (including)
Firefox Mozilla 2.0.0.3 (including) 2.0.0.3 (including)
Firefox Mozilla 2.0.0.4 (including) 2.0.0.4 (including)
Firefox Mozilla 2.0.0.5 (including) 2.0.0.5 (including)
Firefox Mozilla 2.0.0.6 (including) 2.0.0.6 (including)
Firefox Mozilla 2.0.0.7 (including) 2.0.0.7 (including)
Firefox Mozilla 2.0.0.8 (including) 2.0.0.8 (including)
Firefox Mozilla 2.0.0.9 (including) 2.0.0.9 (including)
Firefox Mozilla 2.0.0.10 (including) 2.0.0.10 (including)
Firefox Mozilla 2.0.0.11 (including) 2.0.0.11 (including)
Firefox Mozilla 2.0.0.12 (including) 2.0.0.12 (including)
Firefox Mozilla 2.0.0.13 (including) 2.0.0.13 (including)
Firefox Mozilla 2.0.0.14 (including) 2.0.0.14 (including)
Firefox Mozilla 3.0 (including) 3.0 (including)
Seamonkey Mozilla * 1.1.10 (including)
Seamonkey Mozilla 1.0 (including) 1.0 (including)
Seamonkey Mozilla 1.0-alpha (including) 1.0-alpha (including)
Seamonkey Mozilla 1.0-beta (including) 1.0-beta (including)
Seamonkey Mozilla 1.0.1 (including) 1.0.1 (including)
Seamonkey Mozilla 1.0.2 (including) 1.0.2 (including)
Seamonkey Mozilla 1.0.3 (including) 1.0.3 (including)
Seamonkey Mozilla 1.0.4 (including) 1.0.4 (including)
Seamonkey Mozilla 1.0.5 (including) 1.0.5 (including)
Seamonkey Mozilla 1.0.6 (including) 1.0.6 (including)
Seamonkey Mozilla 1.0.7 (including) 1.0.7 (including)
Seamonkey Mozilla 1.0.8 (including) 1.0.8 (including)
Seamonkey Mozilla 1.0.9 (including) 1.0.9 (including)
Seamonkey Mozilla 1.1 (including) 1.1 (including)
Seamonkey Mozilla 1.1-alpha (including) 1.1-alpha (including)
Seamonkey Mozilla 1.1-beta (including) 1.1-beta (including)
Seamonkey Mozilla 1.1.1 (including) 1.1.1 (including)
Seamonkey Mozilla 1.1.2 (including) 1.1.2 (including)
Seamonkey Mozilla 1.1.3 (including) 1.1.3 (including)
Seamonkey Mozilla 1.1.4 (including) 1.1.4 (including)
Seamonkey Mozilla 1.1.5 (including) 1.1.5 (including)
Seamonkey Mozilla 1.1.6 (including) 1.1.6 (including)
Seamonkey Mozilla 1.1.7 (including) 1.1.7 (including)
Seamonkey Mozilla 1.1.8 (including) 1.1.8 (including)
Seamonkey Mozilla 1.1.9 (including) 1.1.9 (including)
Thunderbird Mozilla * 2.0.0.14 (including)
Thunderbird Mozilla 0.1 (including) 0.1 (including)
Thunderbird Mozilla 0.2 (including) 0.2 (including)
Thunderbird Mozilla 0.3 (including) 0.3 (including)
Thunderbird Mozilla 0.4 (including) 0.4 (including)
Thunderbird Mozilla 0.5 (including) 0.5 (including)
Thunderbird Mozilla 0.6 (including) 0.6 (including)
Thunderbird Mozilla 0.7 (including) 0.7 (including)
Thunderbird Mozilla 0.8 (including) 0.8 (including)
Thunderbird Mozilla 0.9 (including) 0.9 (including)
Thunderbird Mozilla 1.0 (including) 1.0 (including)
Thunderbird Mozilla 1.0.2 (including) 1.0.2 (including)
Thunderbird Mozilla 1.0.5 (including) 1.0.5 (including)
Thunderbird Mozilla 1.0.6 (including) 1.0.6 (including)
Thunderbird Mozilla 1.0.7 (including) 1.0.7 (including)
Thunderbird Mozilla 1.0.8 (including) 1.0.8 (including)
Thunderbird Mozilla 1.5 (including) 1.5 (including)
Thunderbird Mozilla 1.5.0.2 (including) 1.5.0.2 (including)
Thunderbird Mozilla 1.5.0.4 (including) 1.5.0.4 (including)
Thunderbird Mozilla 1.5.0.5 (including) 1.5.0.5 (including)
Thunderbird Mozilla 1.5.0.7 (including) 1.5.0.7 (including)
Thunderbird Mozilla 1.5.0.8 (including) 1.5.0.8 (including)
Thunderbird Mozilla 1.5.0.9 (including) 1.5.0.9 (including)
Thunderbird Mozilla 1.5.0.10 (including) 1.5.0.10 (including)
Thunderbird Mozilla 1.5.0.12 (including) 1.5.0.12 (including)
Thunderbird Mozilla 1.5.0.13 (including) 1.5.0.13 (including)
Thunderbird Mozilla 1.5.0.14 (including) 1.5.0.14 (including)
Thunderbird Mozilla 2.0.0.0 (including) 2.0.0.0 (including)
Thunderbird Mozilla 2.0.0.4 (including) 2.0.0.4 (including)
Thunderbird Mozilla 2.0.0.5 (including) 2.0.0.5 (including)
Thunderbird Mozilla 2.0.0.6 (including) 2.0.0.6 (including)
Thunderbird Mozilla 2.0.0.9 (including) 2.0.0.9 (including)
Thunderbird Mozilla 2.0.0.12 (including) 2.0.0.12 (including)

References