// For flags

CVE-2008-1380

Firefox JavaScript garbage collection crash

Severity Score

9.3
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The JavaScript engine in Mozilla Firefox before 2.0.0.14, Thunderbird before 2.0.0.14, and SeaMonkey before 1.1.10 allows remote attackers to cause a denial of service (garbage collector crash) and possibly have other impacts via a crafted web page. NOTE: this is due to an incorrect fix for CVE-2008-1237.

El motor JavaScript de Mozilla Firefox versiones anteriores a 2.0.0.14, Thunderbird versiones anteriores a 2.0.0.14, y SeaMonkey versiones anteriores a 1.1.10 permite a atacantes remotos provocar una denegación de servicio (caída del colector de basura) y posiblemente tener otros impactos mediante un página web manipulada. NOTA: esto es debido a un parche incorrecto para el CVE-2008-1237.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2008-03-18 CVE Reserved
  • 2008-04-17 CVE Published
  • 2024-08-07 CVE Updated
  • 2024-10-28 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-399: Resource Management Errors
CAPEC
References (50)
URL Tag Source
http://secunia.com/advisories/29793 Third Party Advisory
http://secunia.com/advisories/29828 Third Party Advisory
http://secunia.com/advisories/29883 Third Party Advisory
http://secunia.com/advisories/29908 Third Party Advisory
http://secunia.com/advisories/29911 Third Party Advisory
http://secunia.com/advisories/29912 Third Party Advisory
http://secunia.com/advisories/29947 Third Party Advisory
http://secunia.com/advisories/30012 Third Party Advisory
http://secunia.com/advisories/30029 Third Party Advisory
http://secunia.com/advisories/30192 Third Party Advisory
http://secunia.com/advisories/30327 Third Party Advisory
http://secunia.com/advisories/30620 Third Party Advisory
http://secunia.com/advisories/30717 Third Party Advisory
http://secunia.com/advisories/31023 Third Party Advisory
http://secunia.com/advisories/31377 Third Party Advisory
http://secunia.com/advisories/33434 Third Party Advisory
http://www.kb.cert.org/vuls/id/441529 Third Party Advisory
http://www.mozilla.org/security/announce/2008/mfsa2008-20.html X_refsource_confirm
http://www.securityfocus.com/archive/1/491838/100/0/threaded Mailing List
http://www.securityfocus.com/bid/28818 Vdb Entry
http://www.securitytracker.com/id?1019873 Vdb Entry
http://www.vupen.com/english/advisories/2008/1251/references Vdb Entry
http://www.vupen.com/english/advisories/2008/1793/references Vdb Entry
https://bugzilla.mozilla.org/show_bug.cgi?id=425576 X_refsource_misc
https://exchange.xforce.ibmcloud.com/vulnerabilities/41857 Vdb Entry
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10752 Signature
URL Date SRC
URL Date SRC
http://secunia.com/advisories/29787 2023-11-07
URL Date SRC
http://lists.opensuse.org/opensuse-security-announce/2008-05/msg00000.html 2023-11-07
http://secunia.com/advisories/29860 2023-11-07
http://security.gentoo.org/glsa/glsa-200808-03.xml 2023-11-07
http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.383152 2023-11-07
http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.391769 2023-11-07
http://sunsolve.sun.com/search/document.do?assetkey=1-26-238492-1 2023-11-07
http://www.debian.org/security/2008/dsa-1555 2023-11-07
http://www.debian.org/security/2008/dsa-1558 2023-11-07
http://www.debian.org/security/2008/dsa-1562 2023-11-07
http://www.debian.org/security/2009/dsa-1696 2023-11-07
http://www.gentoo.org/security/en/glsa/glsa-200805-18.xml 2023-11-07
http://www.mandriva.com/security/advisories?name=MDVSA-2008:110 2023-11-07
http://www.novell.com/linux/security/advisories/2008_13_sr.html 2023-11-07
http://www.redhat.com/support/errata/RHSA-2008-0222.html 2023-11-07
http://www.redhat.com/support/errata/RHSA-2008-0223.html 2023-11-07
http://www.redhat.com/support/errata/RHSA-2008-0224.html 2023-11-07
http://www.ubuntu.com/usn/usn-602-1 2023-11-07
https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00407.html 2023-11-07
https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00463.html 2023-11-07
https://www.redhat.com/archives/fedora-package-announce/2008-May/msg00058.html 2023-11-07
https://www.redhat.com/archives/fedora-package-announce/2008-May/msg00074.html 2023-11-07
https://access.redhat.com/security/cve/CVE-2008-1380 2008-04-30
https://bugzilla.redhat.com/show_bug.cgi?id=440518 2008-04-30
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Mozilla
Search vendor "Mozilla"
Firefox
Search vendor "Mozilla" for product "Firefox"
<= 2.0.0.13
Search vendor "Mozilla" for product "Firefox" and version " <= 2.0.0.13"
-
Affected
Mozilla
Search vendor "Mozilla"
Firefox
Search vendor "Mozilla" for product "Firefox"
2.0
Search vendor "Mozilla" for product "Firefox" and version "2.0"
-
Affected
Mozilla
Search vendor "Mozilla"
Firefox
Search vendor "Mozilla" for product "Firefox"
2.0
Search vendor "Mozilla" for product "Firefox" and version "2.0"
beta1
Affected
Mozilla
Search vendor "Mozilla"
Firefox
Search vendor "Mozilla" for product "Firefox"
2.0
Search vendor "Mozilla" for product "Firefox" and version "2.0"
rc2
Affected
Mozilla
Search vendor "Mozilla"
Firefox
Search vendor "Mozilla" for product "Firefox"
2.0
Search vendor "Mozilla" for product "Firefox" and version "2.0"
rc3
Affected
Mozilla
Search vendor "Mozilla"
Firefox
Search vendor "Mozilla" for product "Firefox"
2.0.0.1
Search vendor "Mozilla" for product "Firefox" and version "2.0.0.1"
-
Affected
Mozilla
Search vendor "Mozilla"
Firefox
Search vendor "Mozilla" for product "Firefox"
2.0.0.2
Search vendor "Mozilla" for product "Firefox" and version "2.0.0.2"
-
Affected
Mozilla
Search vendor "Mozilla"
Firefox
Search vendor "Mozilla" for product "Firefox"
2.0.0.3
Search vendor "Mozilla" for product "Firefox" and version "2.0.0.3"
-
Affected
Mozilla
Search vendor "Mozilla"
Firefox
Search vendor "Mozilla" for product "Firefox"
2.0.0.4
Search vendor "Mozilla" for product "Firefox" and version "2.0.0.4"
-
Affected
Mozilla
Search vendor "Mozilla"
Firefox
Search vendor "Mozilla" for product "Firefox"
2.0.0.5
Search vendor "Mozilla" for product "Firefox" and version "2.0.0.5"
-
Affected
Mozilla
Search vendor "Mozilla"
Firefox
Search vendor "Mozilla" for product "Firefox"
2.0.0.6
Search vendor "Mozilla" for product "Firefox" and version "2.0.0.6"
-
Affected
Mozilla
Search vendor "Mozilla"
Firefox
Search vendor "Mozilla" for product "Firefox"
2.0.0.7
Search vendor "Mozilla" for product "Firefox" and version "2.0.0.7"
-
Affected
Mozilla
Search vendor "Mozilla"
Firefox
Search vendor "Mozilla" for product "Firefox"
2.0.0.8
Search vendor "Mozilla" for product "Firefox" and version "2.0.0.8"
-
Affected
Mozilla
Search vendor "Mozilla"
Firefox
Search vendor "Mozilla" for product "Firefox"
2.0.0.9
Search vendor "Mozilla" for product "Firefox" and version "2.0.0.9"
-
Affected
Mozilla
Search vendor "Mozilla"
Firefox
Search vendor "Mozilla" for product "Firefox"
2.0.0.10
Search vendor "Mozilla" for product "Firefox" and version "2.0.0.10"
-
Affected
Mozilla
Search vendor "Mozilla"
Firefox
Search vendor "Mozilla" for product "Firefox"
2.0.0.11
Search vendor "Mozilla" for product "Firefox" and version "2.0.0.11"
-
Affected
Mozilla
Search vendor "Mozilla"
Firefox
Search vendor "Mozilla" for product "Firefox"
2.0.0.12
Search vendor "Mozilla" for product "Firefox" and version "2.0.0.12"
-
Affected
Mozilla
Search vendor "Mozilla"
Seamonkey
Search vendor "Mozilla" for product "Seamonkey"
<= 1.1.9
Search vendor "Mozilla" for product "Seamonkey" and version " <= 1.1.9"
-
Affected
Mozilla
Search vendor "Mozilla"
Seamonkey
Search vendor "Mozilla" for product "Seamonkey"
1.0
Search vendor "Mozilla" for product "Seamonkey" and version "1.0"
-
Affected
Mozilla
Search vendor "Mozilla"
Seamonkey
Search vendor "Mozilla" for product "Seamonkey"
1.0.1
Search vendor "Mozilla" for product "Seamonkey" and version "1.0.1"
-
Affected
Mozilla
Search vendor "Mozilla"
Seamonkey
Search vendor "Mozilla" for product "Seamonkey"
1.0.2
Search vendor "Mozilla" for product "Seamonkey" and version "1.0.2"
-
Affected
Mozilla
Search vendor "Mozilla"
Seamonkey
Search vendor "Mozilla" for product "Seamonkey"
1.0.3
Search vendor "Mozilla" for product "Seamonkey" and version "1.0.3"
-
Affected
Mozilla
Search vendor "Mozilla"
Seamonkey
Search vendor "Mozilla" for product "Seamonkey"
1.0.4
Search vendor "Mozilla" for product "Seamonkey" and version "1.0.4"
-
Affected
Mozilla
Search vendor "Mozilla"
Seamonkey
Search vendor "Mozilla" for product "Seamonkey"
1.0.5
Search vendor "Mozilla" for product "Seamonkey" and version "1.0.5"
-
Affected
Mozilla
Search vendor "Mozilla"
Seamonkey
Search vendor "Mozilla" for product "Seamonkey"
1.0.6
Search vendor "Mozilla" for product "Seamonkey" and version "1.0.6"
-
Affected
Mozilla
Search vendor "Mozilla"
Seamonkey
Search vendor "Mozilla" for product "Seamonkey"
1.0.7
Search vendor "Mozilla" for product "Seamonkey" and version "1.0.7"
-
Affected
Mozilla
Search vendor "Mozilla"
Seamonkey
Search vendor "Mozilla" for product "Seamonkey"
1.0.8
Search vendor "Mozilla" for product "Seamonkey" and version "1.0.8"
-
Affected
Mozilla
Search vendor "Mozilla"
Seamonkey
Search vendor "Mozilla" for product "Seamonkey"
1.0.9
Search vendor "Mozilla" for product "Seamonkey" and version "1.0.9"
-
Affected
Mozilla
Search vendor "Mozilla"
Seamonkey
Search vendor "Mozilla" for product "Seamonkey"
1.0.99
Search vendor "Mozilla" for product "Seamonkey" and version "1.0.99"
-
Affected
Mozilla
Search vendor "Mozilla"
Seamonkey
Search vendor "Mozilla" for product "Seamonkey"
1.1
Search vendor "Mozilla" for product "Seamonkey" and version "1.1"
-
Affected
Mozilla
Search vendor "Mozilla"
Seamonkey
Search vendor "Mozilla" for product "Seamonkey"
1.1.2
Search vendor "Mozilla" for product "Seamonkey" and version "1.1.2"
-
Affected
Mozilla
Search vendor "Mozilla"
Seamonkey
Search vendor "Mozilla" for product "Seamonkey"
1.1.3
Search vendor "Mozilla" for product "Seamonkey" and version "1.1.3"
-
Affected
Mozilla
Search vendor "Mozilla"
Seamonkey
Search vendor "Mozilla" for product "Seamonkey"
1.1.4
Search vendor "Mozilla" for product "Seamonkey" and version "1.1.4"
-
Affected
Mozilla
Search vendor "Mozilla"
Seamonkey
Search vendor "Mozilla" for product "Seamonkey"
1.1.5
Search vendor "Mozilla" for product "Seamonkey" and version "1.1.5"
-
Affected
Mozilla
Search vendor "Mozilla"
Seamonkey
Search vendor "Mozilla" for product "Seamonkey"
1.1.6
Search vendor "Mozilla" for product "Seamonkey" and version "1.1.6"
-
Affected
Mozilla
Search vendor "Mozilla"
Seamonkey
Search vendor "Mozilla" for product "Seamonkey"
1.1.7
Search vendor "Mozilla" for product "Seamonkey" and version "1.1.7"
-
Affected
Mozilla
Search vendor "Mozilla"
Seamonkey
Search vendor "Mozilla" for product "Seamonkey"
1.1.8
Search vendor "Mozilla" for product "Seamonkey" and version "1.1.8"
-
Affected
Mozilla
Search vendor "Mozilla"
Thunderbird
Search vendor "Mozilla" for product "Thunderbird"
<= 2.0.0.13
Search vendor "Mozilla" for product "Thunderbird" and version " <= 2.0.0.13"
-
Affected
Mozilla
Search vendor "Mozilla"
Thunderbird
Search vendor "Mozilla" for product "Thunderbird"
2.0.0.0
Search vendor "Mozilla" for product "Thunderbird" and version "2.0.0.0"
-
Affected
Mozilla
Search vendor "Mozilla"
Thunderbird
Search vendor "Mozilla" for product "Thunderbird"
2.0.0.1
Search vendor "Mozilla" for product "Thunderbird" and version "2.0.0.1"
-
Affected
Mozilla
Search vendor "Mozilla"
Thunderbird
Search vendor "Mozilla" for product "Thunderbird"
2.0.0.2
Search vendor "Mozilla" for product "Thunderbird" and version "2.0.0.2"
-
Affected
Mozilla
Search vendor "Mozilla"
Thunderbird
Search vendor "Mozilla" for product "Thunderbird"
2.0.0.3
Search vendor "Mozilla" for product "Thunderbird" and version "2.0.0.3"
-
Affected
Mozilla
Search vendor "Mozilla"
Thunderbird
Search vendor "Mozilla" for product "Thunderbird"
2.0.0.4
Search vendor "Mozilla" for product "Thunderbird" and version "2.0.0.4"
-
Affected
Mozilla
Search vendor "Mozilla"
Thunderbird
Search vendor "Mozilla" for product "Thunderbird"
2.0.0.5
Search vendor "Mozilla" for product "Thunderbird" and version "2.0.0.5"
-
Affected
Mozilla
Search vendor "Mozilla"
Thunderbird
Search vendor "Mozilla" for product "Thunderbird"
2.0.0.6
Search vendor "Mozilla" for product "Thunderbird" and version "2.0.0.6"
-
Affected
Mozilla
Search vendor "Mozilla"
Thunderbird
Search vendor "Mozilla" for product "Thunderbird"
2.0.0.8
Search vendor "Mozilla" for product "Thunderbird" and version "2.0.0.8"
-
Affected
Mozilla
Search vendor "Mozilla"
Thunderbird
Search vendor "Mozilla" for product "Thunderbird"
2.0.0.9
Search vendor "Mozilla" for product "Thunderbird" and version "2.0.0.9"
-
Affected
Mozilla
Search vendor "Mozilla"
Thunderbird
Search vendor "Mozilla" for product "Thunderbird"
2.0.0.11
Search vendor "Mozilla" for product "Thunderbird" and version "2.0.0.11"
-
Affected
Mozilla
Search vendor "Mozilla"
Thunderbird
Search vendor "Mozilla" for product "Thunderbird"
2.0.0.12
Search vendor "Mozilla" for product "Thunderbird" and version "2.0.0.12"
-
Affected