CVE-2008-4063
Multiple unspecified vulnerabilities in Mozilla Firefox 3.x before 3.0.2 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the layout engine and (1) a…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.96%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple unspecified vulnerabilities in Mozilla Firefox 3.x before 3.0.2 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the layout engine and (1) a zero value of the "this" variable in the nsContentList::Item function; (2) interaction of the indic IME extension, a Hindi language selection, and the "g" character; and (3) interaction of the nsFrameList::SortByContentOrder function with a certain insufficient protection of inline frames.
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 3.96% probability · 90th percentile
- CISA KEV
- Not listed
- Affected
- canonical/ubuntu linux · mozilla/firefox
- Source
- secalert@redhat.com
References
- http://lists.opensuse.org/opensuse-security-announce/2008-10/msg00005.html
- http://secunia.com/advisories/31987Vendor Advisory
- http://secunia.com/advisories/32011Vendor Advisory
- http://secunia.com/advisories/32012Vendor Advisory
- http://secunia.com/advisories/32025Vendor Advisory
- http://secunia.com/advisories/32044Vendor Advisory
- http://secunia.com/advisories/32082Vendor Advisory
- http://secunia.com/advisories/32089Vendor Advisory
- http://secunia.com/advisories/32095Vendor Advisory
- http://secunia.com/advisories/32096Vendor Advisory
- http://secunia.com/advisories/32196Vendor Advisory
- http://secunia.com/advisories/34501Vendor Advisory
- http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.379422
- http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.412123
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-256408-1
- http://www.mozilla.org/security/announce/2008/mfsa2008-42.htmlVendor Advisory
- http://www.redhat.com/support/errata/RHSA-2008-0879.html
- http://www.securityfocus.com/bid/31346
- http://www.securitytracker.com/id?1020916
- http://www.ubuntu.com/usn/usn-645-1
- http://www.ubuntu.com/usn/usn-645-2
- http://www.ubuntu.com/usn/usn-647-1
- http://www.vupen.com/english/advisories/2008/2661
- http://www.vupen.com/english/advisories/2009/0977
- https://bugzilla.mozilla.org/show_bug.cgi?id=413048
- https://bugzilla.mozilla.org/show_bug.cgi?id=433758
- https://bugzilla.mozilla.org/show_bug.cgi?id=444452
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45354
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11151
- https://www.redhat.com/archives/fedora-package-announce/2008-September/msg01335.html
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.