10

CVE-2008-5017

Integer overflow in xpcom/io/nsEscape.cpp in the browser engine in Mozilla Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) via unknown vectors.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MozillaFirefox Version >= 2.0 < 2.0.0.18
MozillaFirefox Version >= 3.0 < 3.0.4
MozillaSeamonkey Version >= 1.0 < 1.1.13
MozillaThunderbird Version >= 2.0 < 2.0.0.18
DebianDebian Linux Version4.0
CanonicalUbuntu Linux Version6.06 SwEditionlts
CanonicalUbuntu Linux Version7.10
CanonicalUbuntu Linux Version8.04 SwEditionlts
CanonicalUbuntu Linux Version8.10
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 17.42% 0.948
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://ubuntu.com/usn/usn-667-1
Third Party Advisory
http://www.us-cert.gov/cas/techalerts/TA08-319A.html
Third Party Advisory
US Government Resource
http://www.securityfocus.com/bid/32281
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id?1021183
Third Party Advisory
VDB Entry