CVE Vulnerabilities

CVE-2008-5502

Published: Dec 17, 2008 | Modified: Nov 08, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
LOW

The layout engine in Mozilla Firefox 3.x before 3.0.5, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to cause a denial of service (crash) via vectors that trigger memory corruption, related to the GetXMLEntity and FastAppendChar functions.

Affected Software

Name Vendor Start Version End Version
Firefox Mozilla 2.0 (including) 2.0.0.19 (excluding)
Firefox Mozilla 3.0 (including) 3.0.5 (excluding)
Seamonkey Mozilla 1.0 (including) 1.1.14 (excluding)
Red Hat Enterprise Linux 2.1 RedHat seamonkey-0:1.0.9-0.25.el2 *
Red Hat Enterprise Linux 3 RedHat seamonkey-0:1.0.9-0.29.el3 *
Red Hat Enterprise Linux 4 RedHat firefox-0:3.0.5-1.el4 *
Red Hat Enterprise Linux 4 RedHat nspr-0:4.7.3-1.el4 *
Red Hat Enterprise Linux 4 RedHat nss-0:3.12.2.0-1.el4 *
Red Hat Enterprise Linux 4 RedHat seamonkey-0:1.0.9-32.el4 *
Red Hat Enterprise Linux 4 RedHat thunderbird-0:1.5.0.12-18.el4 *
Red Hat Enterprise Linux 5 RedHat firefox-0:3.0.5-1.el5_2 *
Red Hat Enterprise Linux 5 RedHat nspr-0:4.7.3-2.el5 *
Red Hat Enterprise Linux 5 RedHat nss-0:3.12.2.0-2.el5 *
Red Hat Enterprise Linux 5 RedHat xulrunner-0:1.9.0.5-1.el5_2 *
Red Hat Enterprise Linux 5 RedHat thunderbird-0:2.0.0.19-1.el5_2 *
Firefox-3.0 Ubuntu gutsy *
Firefox-3.0 Ubuntu hardy *
Firefox-3.0 Ubuntu intrepid *
Firefox-3.0 Ubuntu jaunty *
Firefox-3.0 Ubuntu upstream *
Iceape Ubuntu gutsy *
Iceape Ubuntu upstream *
Mozilla-thunderbird Ubuntu dapper *
Seamonkey Ubuntu hardy *
Seamonkey Ubuntu intrepid *
Seamonkey Ubuntu upstream *
Thunderbird Ubuntu devel *
Thunderbird Ubuntu gutsy *
Thunderbird Ubuntu hardy *
Thunderbird Ubuntu intrepid *
Thunderbird Ubuntu jaunty *
Thunderbird Ubuntu karmic *
Thunderbird Ubuntu upstream *
Xulrunner-1.9 Ubuntu gutsy *
Xulrunner-1.9 Ubuntu hardy *
Xulrunner-1.9 Ubuntu intrepid *
Xulrunner-1.9 Ubuntu jaunty *
Xulrunner-1.9 Ubuntu upstream *

References