Vulnerability Description
The JavaScript engine in Mozilla Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) via vectors related to "insufficient class checking" in the Date class.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox | >= 2.0, < 2.0.0.18 |
| Mozilla | Seamonkey | >= 1.0, < 1.1.13 |
| Mozilla | Thunderbird | >= 2.0, < 2.0.0.18 |
| Debian | Debian Linux | 4.0 |
| Canonical | Ubuntu Linux | 6.06 |
Related Weaknesses (CWE)
References
- http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00004.htmlThird Party Advisory
- http://secunia.com/advisories/32684Third Party Advisory
- http://secunia.com/advisories/32693Third Party Advisory
- http://secunia.com/advisories/32694Third Party Advisory
- http://secunia.com/advisories/32695Third Party Advisory
- http://secunia.com/advisories/32713Third Party Advisory
- http://secunia.com/advisories/32714Third Party Advisory
- http://secunia.com/advisories/32715Third Party Advisory
- http://secunia.com/advisories/32721Third Party Advisory
- http://secunia.com/advisories/32778Third Party Advisory
- http://secunia.com/advisories/32798Third Party Advisory
- http://secunia.com/advisories/32845Third Party Advisory
- http://secunia.com/advisories/32853Third Party Advisory
- http://secunia.com/advisories/33434Third Party Advisory
- http://secunia.com/advisories/34501Third Party Advisory
FAQ
What is CVE-2008-5018?
CVE-2008-5018 is a vulnerability with a CVSS score of 10.0 (HIGH). The JavaScript engine in Mozilla Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of se...
How severe is CVE-2008-5018?
CVE-2008-5018 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2008-5018?
Check the references section above for vendor advisories and patch information. Affected products include: Mozilla Firefox, Mozilla Seamonkey, Mozilla Thunderbird, Debian Debian Linux, Canonical Ubuntu Linux.