CVE Vulnerabilities

CVE-2008-5502

Published: Dec 17, 2008 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

The layout engine in Mozilla Firefox 3.x before 3.0.5, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to cause a denial of service (crash) via vectors that trigger memory corruption, related to the GetXMLEntity and FastAppendChar functions.

Affected Software

NameVendorStart VersionEnd Version
FirefoxMozilla2.0 (including)2.0.0.19 (excluding)
FirefoxMozilla3.0 (including)3.0.5 (excluding)
SeamonkeyMozilla1.0 (including)1.1.14 (excluding)
Red Hat Enterprise Linux 2.1RedHatseamonkey-0:1.0.9-0.25.el2*
Red Hat Enterprise Linux 3RedHatseamonkey-0:1.0.9-0.29.el3*
Red Hat Enterprise Linux 4RedHatfirefox-0:3.0.5-1.el4*
Red Hat Enterprise Linux 4RedHatnspr-0:4.7.3-1.el4*
Red Hat Enterprise Linux 4RedHatnss-0:3.12.2.0-1.el4*
Red Hat Enterprise Linux 4RedHatseamonkey-0:1.0.9-32.el4*
Red Hat Enterprise Linux 4RedHatthunderbird-0:1.5.0.12-18.el4*
Red Hat Enterprise Linux 5RedHatfirefox-0:3.0.5-1.el5_2*
Red Hat Enterprise Linux 5RedHatnspr-0:4.7.3-2.el5*
Red Hat Enterprise Linux 5RedHatnss-0:3.12.2.0-2.el5*
Red Hat Enterprise Linux 5RedHatxulrunner-0:1.9.0.5-1.el5_2*
Red Hat Enterprise Linux 5RedHatthunderbird-0:2.0.0.19-1.el5_2*
Firefox-3.0Ubuntugutsy*
Firefox-3.0Ubuntuhardy*
Firefox-3.0Ubuntuintrepid*
Firefox-3.0Ubuntujaunty*
Firefox-3.0Ubuntuupstream*
IceapeUbuntugutsy*
IceapeUbuntuupstream*
Mozilla-thunderbirdUbuntudapper*
SeamonkeyUbuntuhardy*
SeamonkeyUbuntuintrepid*
SeamonkeyUbuntuupstream*
ThunderbirdUbuntudevel*
ThunderbirdUbuntugutsy*
ThunderbirdUbuntuhardy*
ThunderbirdUbuntuintrepid*
ThunderbirdUbuntujaunty*
ThunderbirdUbuntukarmic*
ThunderbirdUbuntuupstream*
Xulrunner-1.9Ubuntugutsy*
Xulrunner-1.9Ubuntuhardy*
Xulrunner-1.9Ubuntuintrepid*
Xulrunner-1.9Ubuntujaunty*
Xulrunner-1.9Ubuntuupstream*

References