{"api_version":"1","generated_at":"2026-07-23T08:15:49+00:00","cve":"CVE-2008-0017","urls":{"html":"https://cve.report/CVE-2008-0017","api":"https://cve.report/api/cve/CVE-2008-0017.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2008-0017","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2008-0017"},"summary":{"title":"CVE-2008-0017","description":"The http-index-format MIME type parser (nsDirIndexParser) in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 does not check for an allocation failure, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an HTTP index response with a crafted 200 header, which triggers memory corruption and a buffer overflow.","state":"PUBLISHED","assigner":"mitre","published_at":"2008-11-13 11:30:01","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-119","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"9.3","severity":"","vector":"AV:N/AC:M/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://www.securitytracker.com/id?1021185","name":"http://www.securitytracker.com/id?1021185","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"Mozilla Firefox http-index-format MIME Parsing Buffer Overflow Lets Remote Users Execute Arbitrary Code - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/32845","name":"http://secunia.com/advisories/32845","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Debian update for xulrunner - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2009/0977","name":"http://www.vupen.com/english/advisories/2009/0977","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://sunsolve.sun.com/search/document.do?assetkey=1-26-256408-1","name":"http://sunsolve.sun.com/search/document.do?assetkey=1-26-256408-1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"","mime":"","httpstatus":"-1","archivestatus":"404"},{"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2008:228","name":"http://www.mandriva.com/security/advisories?name=MDVSA-2008:228","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Support / Security / Advisories /  / MDVSA-2008:228 | Mandriva","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11005","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11005","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/32281","name":"http://www.securityfocus.com/bid/32281","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"Mozilla Firefox/Thunderbird/SeaMonkey Multiple Remote Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://secunia.com/advisories/32694","name":"http://secunia.com/advisories/32694","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Red Hat update for seamonkey - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.debian.org/security/2008/dsa-1669","name":"http://www.debian.org/security/2008/dsa-1669","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Debian -- Security Information -- DSA-1669-1 xulrunner","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/32853","name":"http://secunia.com/advisories/32853","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Debian update for iceweasel - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.debian.org/security/2008/dsa-1671","name":"http://www.debian.org/security/2008/dsa-1671","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Debian -- Security Information -- DSA-1671-1 iceweasel","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.redhat.com/archives/fedora-package-announce/2008-November/msg00366.html","name":"https://www.redhat.com/archives/fedora-package-announce/2008-November/msg00366.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"[SECURITY] Fedora 8 Update: firefox-2.0.0.18-1.fc8","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.debian.org/security/2009/dsa-1697","name":"http://www.debian.org/security/2009/dsa-1697","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Debian -- Security Information -- DSA-1697-1 iceape","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/32693","name":"http://secunia.com/advisories/32693","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Mozilla Firefox 2 Multiple Vulnerabilities - Secunia Advisories - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=443299","name":"https://bugzilla.mozilla.org/show_bug.cgi?id=443299","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Vendor Advisory"],"title":"Bug 443299 – Investigate possible buffer overflow in nsDirIndexParser","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.us-cert.gov/cas/techalerts/TA08-319A.html","name":"http://www.us-cert.gov/cas/techalerts/TA08-319A.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","US Government Resource"],"title":"US-CERT Technical Cyber Security Alert TA08-319A -- Mozilla Updates for Multiple Vulnerabilities","mime":"text/xml","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/33433","name":"http://secunia.com/advisories/33433","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Debian update for iceape - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00004.html","name":"http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00004.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"[security-announce] SUSE Security Announcement: Mozilla (SUSE-SA:2008:05","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2008:230","name":"http://www.mandriva.com/security/advisories?name=MDVSA-2008:230","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Support / Security / Advisories /  / MDVSA-2008:230 | Mandriva","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/32778","name":"http://secunia.com/advisories/32778","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Ubuntu update for firefox, firefox-3.0, and xulrunner-1.9 - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/32713","name":"http://secunia.com/advisories/32713","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Mozilla Firefox 3 Multiple Vulnerabilities - Secunia Advisories - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/32721","name":"http://secunia.com/advisories/32721","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Fedora update for firefox and xulrunner - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.redhat.com/support/errata/RHSA-2008-0978.html","name":"http://www.redhat.com/support/errata/RHSA-2008-0978.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.redhat.com/archives/fedora-package-announce/2008-November/msg00385.html","name":"https://www.redhat.com/archives/fedora-package-announce/2008-November/msg00385.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"[SECURITY] Fedora 9 Update: xulrunner-1.9.0.4-1.fc9","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/34501","name":"http://secunia.com/advisories/34501","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Sun Solaris Firefox Multiple Vulnerabilities - Secunia Advisories - Vulnerability Information - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.mozilla.org/security/announce/2008/mfsa2008-54.html","name":"http://www.mozilla.org/security/announce/2008/mfsa2008-54.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"MFSA 2008-54: Buffer overflow in http-index-format parser","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/32695","name":"http://secunia.com/advisories/32695","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Red Hat update for firefox - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/32684","name":"http://secunia.com/advisories/32684","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Fedora update for firefox - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.redhat.com/support/errata/RHSA-2008-0977.html","name":"http://www.redhat.com/support/errata/RHSA-2008-0977.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2008/3146","name":"http://www.vupen.com/english/advisories/2008/3146","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/32714","name":"http://secunia.com/advisories/32714","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Mozilla SeaMonkey Multiple Vulnerabilities - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://ubuntu.com/usn/usn-667-1","name":"http://ubuntu.com/usn/usn-667-1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"USN-667-1: Firefox and xulrunner vulnerabilities | Ubuntu","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.iss.net/threats/311.html","name":"http://www.iss.net/threats/311.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Mozilla Unchecked Allocation RCE","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2008-0017","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2008-0017","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2008","cve_id":"17","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mozilla","cpe5":"firefox","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T07:32:23.353Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"ADV-2008-3146","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2008/3146"},{"name":"1021185","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1021185"},{"name":"DSA-1697","tags":["vendor-advisory","x_refsource_DEBIAN","x_transferred"],"url":"http://www.debian.org/security/2009/dsa-1697"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=443299"},{"name":"DSA-1671","tags":["vendor-advisory","x_refsource_DEBIAN","x_transferred"],"url":"http://www.debian.org/security/2008/dsa-1671"},{"name":"32281","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/32281"},{"name":"FEDORA-2008-9667","tags":["vendor-advisory","x_refsource_FEDORA","x_transferred"],"url":"https://www.redhat.com/archives/fedora-package-announce/2008-November/msg00366.html"},{"name":"32713","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/32713"},{"name":"RHSA-2008:0977","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2008-0977.html"},{"name":"MDVSA-2008:230","tags":["vendor-advisory","x_refsource_MANDRIVA","x_transferred"],"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2008:230"},{"name":"ADV-2009-0977","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2009/0977"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.mozilla.org/security/announce/2008/mfsa2008-54.html"},{"name":"32695","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/32695"},{"name":"RHSA-2008:0978","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2008-0978.html"},{"name":"DSA-1669","tags":["vendor-advisory","x_refsource_DEBIAN","x_transferred"],"url":"http://www.debian.org/security/2008/dsa-1669"},{"name":"32778","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/32778"},{"name":"FEDORA-2008-9669","tags":["vendor-advisory","x_refsource_FEDORA","x_transferred"],"url":"https://www.redhat.com/archives/fedora-package-announce/2008-November/msg00385.html"},{"name":"33433","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/33433"},{"name":"256408","tags":["vendor-advisory","x_refsource_SUNALERT","x_transferred"],"url":"http://sunsolve.sun.com/search/document.do?assetkey=1-26-256408-1"},{"name":"SUSE-SA:2008:055","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00004.html"},{"name":"32694","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/32694"},{"name":"32721","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/32721"},{"name":"TA08-319A","tags":["third-party-advisory","x_refsource_CERT","x_transferred"],"url":"http://www.us-cert.gov/cas/techalerts/TA08-319A.html"},{"name":"32853","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/32853"},{"name":"oval:org.mitre.oval:def:11005","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11005"},{"name":"32693","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/32693"},{"name":"MDVSA-2008:228","tags":["vendor-advisory","x_refsource_MANDRIVA","x_transferred"],"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2008:228"},{"name":"32845","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/32845"},{"name":"20081113 Mozilla Unchecked Allocation Remote Code Execution","tags":["third-party-advisory","x_refsource_ISS","x_transferred"],"url":"http://www.iss.net/threats/311.html"},{"name":"32684","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/32684"},{"name":"USN-667-1","tags":["vendor-advisory","x_refsource_UBUNTU","x_transferred"],"url":"http://ubuntu.com/usn/usn-667-1"},{"name":"32714","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/32714"},{"name":"34501","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/34501"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2008-11-12T00:00:00.000Z","descriptions":[{"lang":"en","value":"The http-index-format MIME type parser (nsDirIndexParser) in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 does not check for an allocation failure, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an HTTP index response with a crafted 200 header, which triggers memory corruption and a buffer overflow."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-09-28T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"ADV-2008-3146","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2008/3146"},{"name":"1021185","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1021185"},{"name":"DSA-1697","tags":["vendor-advisory","x_refsource_DEBIAN"],"url":"http://www.debian.org/security/2009/dsa-1697"},{"tags":["x_refsource_MISC"],"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=443299"},{"name":"DSA-1671","tags":["vendor-advisory","x_refsource_DEBIAN"],"url":"http://www.debian.org/security/2008/dsa-1671"},{"name":"32281","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/32281"},{"name":"FEDORA-2008-9667","tags":["vendor-advisory","x_refsource_FEDORA"],"url":"https://www.redhat.com/archives/fedora-package-announce/2008-November/msg00366.html"},{"name":"32713","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/32713"},{"name":"RHSA-2008:0977","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2008-0977.html"},{"name":"MDVSA-2008:230","tags":["vendor-advisory","x_refsource_MANDRIVA"],"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2008:230"},{"name":"ADV-2009-0977","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2009/0977"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.mozilla.org/security/announce/2008/mfsa2008-54.html"},{"name":"32695","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/32695"},{"name":"RHSA-2008:0978","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2008-0978.html"},{"name":"DSA-1669","tags":["vendor-advisory","x_refsource_DEBIAN"],"url":"http://www.debian.org/security/2008/dsa-1669"},{"name":"32778","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/32778"},{"name":"FEDORA-2008-9669","tags":["vendor-advisory","x_refsource_FEDORA"],"url":"https://www.redhat.com/archives/fedora-package-announce/2008-November/msg00385.html"},{"name":"33433","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/33433"},{"name":"256408","tags":["vendor-advisory","x_refsource_SUNALERT"],"url":"http://sunsolve.sun.com/search/document.do?assetkey=1-26-256408-1"},{"name":"SUSE-SA:2008:055","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00004.html"},{"name":"32694","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/32694"},{"name":"32721","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/32721"},{"name":"TA08-319A","tags":["third-party-advisory","x_refsource_CERT"],"url":"http://www.us-cert.gov/cas/techalerts/TA08-319A.html"},{"name":"32853","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/32853"},{"name":"oval:org.mitre.oval:def:11005","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11005"},{"name":"32693","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/32693"},{"name":"MDVSA-2008:228","tags":["vendor-advisory","x_refsource_MANDRIVA"],"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2008:228"},{"name":"32845","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/32845"},{"name":"20081113 Mozilla Unchecked Allocation Remote Code Execution","tags":["third-party-advisory","x_refsource_ISS"],"url":"http://www.iss.net/threats/311.html"},{"name":"32684","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/32684"},{"name":"USN-667-1","tags":["vendor-advisory","x_refsource_UBUNTU"],"url":"http://ubuntu.com/usn/usn-667-1"},{"name":"32714","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/32714"},{"name":"34501","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/34501"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2008-0017","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The http-index-format MIME type parser (nsDirIndexParser) in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 does not check for an allocation failure, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an HTTP index response with a crafted 200 header, which triggers memory corruption and a buffer overflow."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"ADV-2008-3146","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2008/3146"},{"name":"1021185","refsource":"SECTRACK","url":"http://www.securitytracker.com/id?1021185"},{"name":"DSA-1697","refsource":"DEBIAN","url":"http://www.debian.org/security/2009/dsa-1697"},{"name":"https://bugzilla.mozilla.org/show_bug.cgi?id=443299","refsource":"MISC","url":"https://bugzilla.mozilla.org/show_bug.cgi?id=443299"},{"name":"DSA-1671","refsource":"DEBIAN","url":"http://www.debian.org/security/2008/dsa-1671"},{"name":"32281","refsource":"BID","url":"http://www.securityfocus.com/bid/32281"},{"name":"FEDORA-2008-9667","refsource":"FEDORA","url":"https://www.redhat.com/archives/fedora-package-announce/2008-November/msg00366.html"},{"name":"32713","refsource":"SECUNIA","url":"http://secunia.com/advisories/32713"},{"name":"RHSA-2008:0977","refsource":"REDHAT","url":"http://www.redhat.com/support/errata/RHSA-2008-0977.html"},{"name":"MDVSA-2008:230","refsource":"MANDRIVA","url":"http://www.mandriva.com/security/advisories?name=MDVSA-2008:230"},{"name":"ADV-2009-0977","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2009/0977"},{"name":"http://www.mozilla.org/security/announce/2008/mfsa2008-54.html","refsource":"CONFIRM","url":"http://www.mozilla.org/security/announce/2008/mfsa2008-54.html"},{"name":"32695","refsource":"SECUNIA","url":"http://secunia.com/advisories/32695"},{"name":"RHSA-2008:0978","refsource":"REDHAT","url":"http://www.redhat.com/support/errata/RHSA-2008-0978.html"},{"name":"DSA-1669","refsource":"DEBIAN","url":"http://www.debian.org/security/2008/dsa-1669"},{"name":"32778","refsource":"SECUNIA","url":"http://secunia.com/advisories/32778"},{"name":"FEDORA-2008-9669","refsource":"FEDORA","url":"https://www.redhat.com/archives/fedora-package-announce/2008-November/msg00385.html"},{"name":"33433","refsource":"SECUNIA","url":"http://secunia.com/advisories/33433"},{"name":"256408","refsource":"SUNALERT","url":"http://sunsolve.sun.com/search/document.do?assetkey=1-26-256408-1"},{"name":"SUSE-SA:2008:055","refsource":"SUSE","url":"http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00004.html"},{"name":"32694","refsource":"SECUNIA","url":"http://secunia.com/advisories/32694"},{"name":"32721","refsource":"SECUNIA","url":"http://secunia.com/advisories/32721"},{"name":"TA08-319A","refsource":"CERT","url":"http://www.us-cert.gov/cas/techalerts/TA08-319A.html"},{"name":"32853","refsource":"SECUNIA","url":"http://secunia.com/advisories/32853"},{"name":"oval:org.mitre.oval:def:11005","refsource":"OVAL","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11005"},{"name":"32693","refsource":"SECUNIA","url":"http://secunia.com/advisories/32693"},{"name":"MDVSA-2008:228","refsource":"MANDRIVA","url":"http://www.mandriva.com/security/advisories?name=MDVSA-2008:228"},{"name":"32845","refsource":"SECUNIA","url":"http://secunia.com/advisories/32845"},{"name":"20081113 Mozilla Unchecked Allocation Remote Code Execution","refsource":"ISS","url":"http://www.iss.net/threats/311.html"},{"name":"32684","refsource":"SECUNIA","url":"http://secunia.com/advisories/32684"},{"name":"USN-667-1","refsource":"UBUNTU","url":"http://ubuntu.com/usn/usn-667-1"},{"name":"32714","refsource":"SECUNIA","url":"http://secunia.com/advisories/32714"},{"name":"34501","refsource":"SECUNIA","url":"http://secunia.com/advisories/34501"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2008-0017","datePublished":"2008-11-13T11:00:00.000Z","dateReserved":"2007-12-13T00:00:00.000Z","dateUpdated":"2024-08-07T07:32:23.353Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2008-11-13 11:30:01","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-119","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":8.6,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*","versionStartIncluding":"2.0","versionEndExcluding":"2.0.0.18","matchCriteriaId":"151CBE7B-E10C-423C-9EE8-5A564FD7A168"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*","versionStartIncluding":"3.0","versionEndExcluding":"3.0.4","matchCriteriaId":"63B71385-5551-4021-A899-C995B3EBA68F"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:*","versionStartIncluding":"1.0","versionEndExcluding":"1.1.13","matchCriteriaId":"D8CF8688-28E3-408B-9167-0C36DB2765FA"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:canonical:ubuntu_linux:6.06:*:*:*:lts:*:*:*","matchCriteriaId":"5C18C3CD-969B-4AA3-AE3A-BA4A188F8BFF"},{"vulnerable":true,"criteria":"cpe:2.3:o:canonical:ubuntu_linux:7.10:*:*:*:*:*:*:*","matchCriteriaId":"823BF8BE-2309-4F67-A5E2-EAD98F723468"},{"vulnerable":true,"criteria":"cpe:2.3:o:canonical:ubuntu_linux:8.04:*:*:*:lts:*:*:*","matchCriteriaId":"C91D2DBF-6DA7-4BA2-9F29-8BD2725A4701"},{"vulnerable":true,"criteria":"cpe:2.3:o:canonical:ubuntu_linux:8.10:*:*:*:*:*:*:*","matchCriteriaId":"4747CC68-FAF4-482F-929A-9DA6C24CB663"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:debian:debian_linux:4.0:*:*:*:*:*:*:*","matchCriteriaId":"0F92AB32-E7DE-43F4-B877-1F41FA162EC7"},{"vulnerable":true,"criteria":"cpe:2.3:o:debian:debian_linux:5.0:*:*:*:*:*:*:*","matchCriteriaId":"8C757774-08E7-40AA-B532-6F705C8F7639"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2008","CveId":"17","Ordinal":"1","Title":"CVE-2008-0017","CVE":"CVE-2008-0017","Year":"2008"},"notes":[{"CveYear":"2008","CveId":"17","Ordinal":"1","NoteData":"The http-index-format MIME type parser (nsDirIndexParser) in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 does not check for an allocation failure, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an HTTP index response with a crafted 200 header, which triggers memory corruption and a buffer overflow.","Type":"Description","Title":"CVE-2008-0017"},{"CveYear":"2008","CveId":"17","Ordinal":"2","NoteData":"2008-11-13","Type":"Other","Title":"Published"},{"CveYear":"2008","CveId":"17","Ordinal":"3","NoteData":"2017-09-28","Type":"Other","Title":"Modified"}]}}}