V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2008-5013
DEB
CriticalConfirmedExploit available

Mozilla Firefox 2.x before 2.0.0.18 and SeaMonkey 1.x before 1.1.13 do not properly check when the Flash module has been dynamically unload…

CVSS
9.3
Critical
EPSS
0.24
p95
Published
2008-01-01
Updated
2008-01-01
Description

Mozilla Firefox 2.x before 2.0.0.18 and SeaMonkey 1.x before 1.1.13 do not properly check when the Flash module has been dynamically unloaded properly, which allows remote attackers to execute arbitrary code via a crafted SWF file that "dynamically unloads itself from an outside JavaScript function," which triggers an access of an expired memory address.

Tags · CWE
CWE-399
Affected products
Firefox ≤ 2.0.0.17FirefoxSeamonkey ≤ 1.1.12Seamonkey
CVSS vector
AV:N/AC:M/Au:N/C:C/I:C/A:C
Timeline
2008-01-01
Published
2008-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: M
Medium
Authentication
Au: N
None (N)
Confidentiality Impact
C: C
Complete
Integrity Impact
I: C
Complete
Availability Impact
A: C
Complete
Exploit indicators
EPSS
0.239 · p95
Known exploited (KEV)
No
Known exploits — Сканер-ВС
32466
exploitdb · https://www.exploit-db.com/exploits/32466
Enterprise
9663
exploitdb · https://www.exploit-db.com/exploits/9663
Enterprise
Affected software
ProductVendorStatus
firefoxTracked
firefox-3.0Tracked
iceapeTracked
iceweaselTracked
seamonkeyTracked
seamonkeyTracked
seamonkeyTracked
seamonkeyTracked
thunderbirdTracked
xulrunnerTracked
xulrunnerTracked
xulrunner-1.9Tracked
firefox*Tracked
seamonkey*Tracked