CVE-2008-5021
Summary
| CVE | CVE-2008-5021 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2008-11-13 11:30:00 UTC |
| Updated | 2024-02-02 17:07:00 UTC |
| Description | nsFrameManager in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by modifying properties of a file input element while it is still being initialized, then using the blur method to access uninitialized memory. |
Risk And Classification
Problem Types: CWE-362
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Canonical | Ubuntu Linux | 6.06 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 7.10 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 8.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 8.10 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 6.06 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 7.10 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 8.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 8.10 | All | All | All |
| Operating System | Debian | Debian Linux | 4.0 | All | All | All |
| Operating System | Debian | Debian Linux | 4.0 | All | All | All |
| Operating System | Fedoraproject | Fedora | 8 | All | All | All |
| Operating System | Fedoraproject | Fedora | 9 | All | All | All |
| Application | Mozilla | Firefox | All | All | All | All |
| Application | Mozilla | Firefox | All | All | All | All |
| Application | Mozilla | Seamonkey | All | All | All | All |
| Application | Mozilla | Seamonkey | All | All | All | All |
| Application | Mozilla | Thunderbird | All | All | All | All |
| Application | Mozilla | Thunderbird | All | All | All | All |
| Operating System | Novell | Linux Desktop | 9 | All | All | All |
| Operating System | Novell | Open Enterprise Server | - | All | All | All |
| Operating System | Opensuse | Opensuse | 10.2 | All | All | All |
| Operating System | Opensuse | Opensuse | 10.3 | All | All | All |
| Operating System | Opensuse | Opensuse | 11.0 | All | All | All |
| Application | Suse | Linux Enterprise Debuginfo | 10 | sp2 | All | All |
| Operating System | Suse | Linux Enterprise Desktop | 10 | - | All | All |
| Operating System | Suse | Linux Enterprise Server | 10 | sp1 | All | All |
| Operating System | Suse | Linux Enterprise Server | 9 | All | All | All |
| Operating System | Suse | Linux Enterprise Software Development Kit | 10 | sp1 | All | All |
| Operating System | Suse | Linux Enterprise Software Development Kit | 10 | sp2 | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Support | REDHAT | www.redhat.com | Third Party Advisory |
| Ubuntu update for firefox, firefox-3.0, and xulrunner-1.9 - Secunia.com | SECUNIA | secunia.com | Third Party Advisory |
| Repository / Oval Repository | OVAL | oval.cisecurity.org | Third Party Advisory |
| Mozilla Thunderbird Multiple Vulnerabilities - Secunia Advisories - Vulnerability Information - Secunia.com | SECUNIA | secunia.com | Third Party Advisory |
| Debian update for icedove - Secunia.com | SECUNIA | secunia.com | Third Party Advisory |
| MFSA 2008-55: Crash and remote code execution in nsFrameManager | CONFIRM | www.mozilla.org | Vendor Advisory |
| [SECURITY] Fedora 9 Update: xulrunner-1.9.0.4-1.fc9 | FEDORA | www.redhat.com | Third Party Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | Third Party Advisory |
| Fedora update for firefox - Secunia.com | SECUNIA | secunia.com | Third Party Advisory |
| 256408 | SUNALERT | sunsolve.sun.com | Broken Link |
| Debian update for xulrunner - Secunia.com | SECUNIA | secunia.com | Third Party Advisory |
| Support / Security / Advisories / / MDVSA-2008:230 | Mandriva | MANDRIVA | www.mandriva.com | Third Party Advisory |
| Debian -- Security Information -- DSA-1696-1 icedove | DEBIAN | www.debian.org | Third Party Advisory |
| Mozilla SeaMonkey Multiple Vulnerabilities - Secunia.com | SECUNIA | secunia.com | Third Party Advisory |
| Bug 460002 – It's possible to circumvent the inner window check in nsXMLHttpRequest::NotifyEventListeners() | MISC | bugzilla.mozilla.org | Issue Tracking, Vendor Advisory |
| Mozilla Firefox 2 Multiple Vulnerabilities - Secunia Advisories - Vulnerability Intelligence - Secunia.com | SECUNIA | secunia.com | Third Party Advisory |
| [SECURITY] Fedora 8 Update: firefox-2.0.0.18-1.fc8 | FEDORA | www.redhat.com | Third Party Advisory |
| Mozilla Firefox nsFrameManager Memory Access Bug Lets Remote Users Execute Arbitrary Code - SecurityTracker | SECTRACK | www.securitytracker.com | Third Party Advisory, VDB Entry |
| Debian update for iceweasel - Secunia.com | SECUNIA | secunia.com | Third Party Advisory |
| Support / Security / Advisories / / MDVSA-2008:228 | Mandriva | MANDRIVA | www.mandriva.com | Third Party Advisory |
| Sun Solaris Firefox Multiple Vulnerabilities - Secunia Advisories - Vulnerability Information - Secunia.com | SECUNIA | secunia.com | Third Party Advisory |
| Red Hat update for seamonkey - Secunia.com | SECUNIA | secunia.com | Third Party Advisory |
| Debian -- Security Information -- DSA-1671-1 iceweasel | DEBIAN | www.debian.org | Third Party Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | Third Party Advisory |
| Red Hat update for thunderbird - Secunia.com | SECUNIA | secunia.com | Third Party Advisory |
| USN-667-1: Firefox and xulrunner vulnerabilities | Ubuntu | UBUNTU | ubuntu.com | Third Party Advisory |
| Mozilla Firefox 3 Multiple Vulnerabilities - Secunia Advisories - Vulnerability Intelligence - Secunia.com | SECUNIA | secunia.com | Third Party Advisory |
| Fedora update for firefox and xulrunner - Secunia.com | SECUNIA | secunia.com | Third Party Advisory |
| Mozilla Firefox/Thunderbird/SeaMonkey Multiple Remote Vulnerabilities | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Support | REDHAT | www.redhat.com | Third Party Advisory |
| Support | REDHAT | www.redhat.com | Third Party Advisory |
| Debian -- Security Information -- DSA-1669-1 xulrunner | DEBIAN | www.debian.org | Third Party Advisory |
| US-CERT Technical Cyber Security Alert TA08-319A -- Mozilla Updates for Multiple Vulnerabilities | CERT | www.us-cert.gov | Third Party Advisory, US Government Resource |
| Debian update for iceape - Secunia.com | SECUNIA | secunia.com | Third Party Advisory |
| Debian -- Security Information -- DSA-1697-1 iceape | DEBIAN | www.debian.org | Third Party Advisory |
| [security-announce] SUSE Security Announcement: Mozilla (SUSE-SA:2008:05 | SUSE | lists.opensuse.org | Third Party Advisory |
| Red Hat update for firefox - Secunia.com | SECUNIA | secunia.com | Third Party Advisory |
| Support / Security / Advisories / / MDVSA-2008:235 | Mandriva | MANDRIVA | www.mandriva.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.