Sploitus

CVE-2008-4062

1 known exploit for CVE-2008-4062

Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the JavaScript engine and (1) misinterpretation of the characteristics of Namespace and QName in jsxml.c, (2) misuse of signed integers in the nsEscapeCount function in nsEscape.cpp, and (3) interaction of JavaScript garbage collection with certain use of an NPObject in the nsNPObjWrapper::GetNewOrUsed function in nsJSNPRuntime.cpp.

Mozilla Firefox
< 2.0.0.17, 3.0.2
Mozilla Seamonkey
< 1.1.12
Mozilla Thunderbird
< 2.0.0.17
Fix
Available
CVSS 2.0
10.0 HIGH
EPSS
5.0% (92th percentile)
Weakness
CWE-399
NVD status
Modified
Published
2008-09-24
CVE-2008-4062 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2008-4062

Proof-of-concept code and exploit modules indexed by Sploitus