CVE-2008-5502

The layout engine in Mozilla Firefox 3.x before 3.0.5, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to cause a denial of service (crash) via vectors that trigger memory corruption, related to the GetXMLEntity and FastAppendChar functions.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:canonical:ubuntu_linux:8.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:8.10:*:*:*:*:*:*:*

History

No history.

Information

Published : 2008-12-17 23:30

Updated : 2023-12-10 10:51


NVD link : CVE-2008-5502

Mitre link : CVE-2008-5502

CVE.ORG link : CVE-2008-5502


JSON object : View

Products Affected

canonical

  • ubuntu_linux

mozilla

  • seamonkey
  • firefox
CWE
CWE-399

Resource Management Errors