HIGH · 9.3

CVE-2008-5021

nsFrameManager in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) a...

Vulnerability Description

nsFrameManager in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by modifying properties of a file input element while it is still being initialized, then using the blur method to access uninitialized memory.

CVSS Score

9.3

HIGH

AV:N/AC:M/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
MozillaFirefox>= 2.0, < 2.0.0.18
MozillaSeamonkey>= 1.0, < 1.1.13
MozillaThunderbird>= 2.0, < 2.0.0.18
DebianDebian Linux4.0
CanonicalUbuntu Linux6.06
FedoraprojectFedora8
SuseLinux Enterprise Debuginfo10
NovellLinux Desktop9
NovellOpen Enterprise Server-
OpensuseOpensuse10.2
SuseLinux Enterprise Desktop10
SuseLinux Enterprise Server9
SuseLinux Enterprise Software Development Kit10

Related Weaknesses (CWE)

References

FAQ

What is CVE-2008-5021?

CVE-2008-5021 is a vulnerability with a CVSS score of 9.3 (HIGH). nsFrameManager in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) a...

How severe is CVE-2008-5021?

CVE-2008-5021 has been rated HIGH with a CVSS base score of 9.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2008-5021?

Check the references section above for vendor advisories and patch information. Affected products include: Mozilla Firefox, Mozilla Seamonkey, Mozilla Thunderbird, Debian Debian Linux, Canonical Ubuntu Linux.