Vulnerability Description
The layout engine in Mozilla Firefox 3.x before 3.0.4, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) via multiple vectors that trigger an assertion failure or other consequences.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox | <= 3.0.3 |
| Mozilla | Seamonkey | <= 1.1.12 |
| Mozilla | Thunderbird | <= 2.0.0.17 |
Related Weaknesses (CWE)
References
- http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00004.html
- http://secunia.com/advisories/32684
- http://secunia.com/advisories/32694
- http://secunia.com/advisories/32695
- http://secunia.com/advisories/32713
- http://secunia.com/advisories/32721
- http://secunia.com/advisories/32778
- http://secunia.com/advisories/32798
- http://secunia.com/advisories/34501
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-256408-1
- http://ubuntu.com/usn/usn-667-1
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:230
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:235
- http://www.mozilla.org/security/announce/2008/mfsa2008-52.htmlVendor Advisory
- http://www.redhat.com/support/errata/RHSA-2008-0976.html
FAQ
What is CVE-2008-5016?
CVE-2008-5016 is a vulnerability with a CVSS score of 5.0 (MEDIUM). The layout engine in Mozilla Firefox 3.x before 3.0.4, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) via multiple vector...
How severe is CVE-2008-5016?
CVE-2008-5016 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2008-5016?
Check the references section above for vendor advisories and patch information. Affected products include: Mozilla Firefox, Mozilla Seamonkey, Mozilla Thunderbird.