V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2008-0017
DEB
CriticalConfirmedExploit available

The http-index-format MIME type parser (nsDirIndexParser) in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, and SeaMonkey 1.x befor…

CVSS
9.3
Critical
EPSS
0.14
p94
Published
2008-01-01
Updated
2008-01-01
Description

The http-index-format MIME type parser (nsDirIndexParser) in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 does not check for an allocation failure, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an HTTP index response with a crafted 200 header, which triggers memory corruption and a buffer overflow.

Tags · CWE
RCE
CWE-119
CAPEC-8
CAPEC-9
CAPEC-10
CAPEC-14
CAPEC-24
CAPEC-42
CAPEC-44
CAPEC-45
CAPEC-46
CAPEC-47
CAPEC-100
CAPEC-123
Affected products
Debian_linux
CVSS vector
AV:N/AC:M/Au:N/C:C/I:C/A:C
Timeline
2008-01-01
Published
2008-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: M
Medium
Authentication
Au: N
None (N)
Confidentiality Impact
C: C
Complete
Integrity Impact
I: C
Complete
Availability Impact
A: C
Complete
Exploit indicators
EPSS
0.145 · p94
Known exploited (KEV)
No
Known exploits — Сканер-ВС
32466
exploitdb · https://www.exploit-db.com/exploits/32466
Enterprise
9663
exploitdb · https://www.exploit-db.com/exploits/9663
Enterprise
Affected software
ProductVendorStatus
devhelpTracked
firefoxTracked
firefoxTracked
firefoxTracked
firefox-3.0Tracked
iceapeTracked
iceweaselTracked
nssTracked
nssTracked
seamonkeyTracked
seamonkeyTracked
seamonkeyTracked
seamonkeyTracked
xulrunnerTracked
xulrunnerTracked
xulrunnerTracked
xulrunner-1.9Tracked
yelpTracked
debian_linux*Tracked
firefox*Tracked