Description
The JavaScript engine in Mozilla Firefox before 2.0.0.14, Thunderbird before 2.0.0.14, and SeaMonkey before 1.1.10 allows remote attackers to cause a denial of service (garbage collector crash) and possibly have other impacts via a crafted web page. NOTE: this is due to an incorrect fix for CVE-2008-1237.
Published: 2008-04-17
Score: 9.3 Critical
EPSS: 17.0% Moderate
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-1555-1 New iceweasel packages fix arbitrary code execution
Debian DSA Debian DSA DSA-1558-1 New xulrunner packages fix arbitrary code execution
Debian DSA Debian DSA DSA-1562-1 New iceape packages fix arbitrary code execution
Debian DSA Debian DSA DSA-1696-1 New icedove packages fix several vulnerabilities
Ubuntu USN Ubuntu USN USN-602-1 Firefox vulnerabilities
References
Link Providers
http://lists.opensuse.org/opensuse-security-announce/2008-05/msg00000.html cve-icon cve-icon
http://secunia.com/advisories/29787 cve-icon cve-icon
http://secunia.com/advisories/29793 cve-icon cve-icon
http://secunia.com/advisories/29828 cve-icon cve-icon
http://secunia.com/advisories/29860 cve-icon cve-icon
http://secunia.com/advisories/29883 cve-icon cve-icon
http://secunia.com/advisories/29908 cve-icon cve-icon
http://secunia.com/advisories/29911 cve-icon cve-icon
http://secunia.com/advisories/29912 cve-icon cve-icon
http://secunia.com/advisories/29947 cve-icon cve-icon
http://secunia.com/advisories/30012 cve-icon cve-icon
http://secunia.com/advisories/30029 cve-icon cve-icon
http://secunia.com/advisories/30192 cve-icon cve-icon
http://secunia.com/advisories/30327 cve-icon cve-icon
http://secunia.com/advisories/30620 cve-icon cve-icon
http://secunia.com/advisories/30717 cve-icon cve-icon
http://secunia.com/advisories/31023 cve-icon cve-icon
http://secunia.com/advisories/31377 cve-icon cve-icon
http://secunia.com/advisories/33434 cve-icon cve-icon
http://security.gentoo.org/glsa/glsa-200808-03.xml cve-icon cve-icon
http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.383152 cve-icon cve-icon
http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.391769 cve-icon cve-icon
http://sunsolve.sun.com/search/document.do?assetkey=1-26-238492-1 cve-icon cve-icon
http://www.debian.org/security/2008/dsa-1555 cve-icon cve-icon
http://www.debian.org/security/2008/dsa-1558 cve-icon cve-icon
http://www.debian.org/security/2008/dsa-1562 cve-icon cve-icon
http://www.debian.org/security/2009/dsa-1696 cve-icon cve-icon
http://www.gentoo.org/security/en/glsa/glsa-200805-18.xml cve-icon cve-icon
http://www.kb.cert.org/vuls/id/441529 cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDVSA-2008:110 cve-icon cve-icon
http://www.mozilla.org/security/announce/2008/mfsa2008-20.html cve-icon cve-icon
http://www.novell.com/linux/security/advisories/2008_13_sr.html cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2008-0222.html cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2008-0223.html cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2008-0224.html cve-icon cve-icon
http://www.securityfocus.com/archive/1/491838/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/bid/28818 cve-icon cve-icon
http://www.securitytracker.com/id?1019873 cve-icon cve-icon
http://www.ubuntu.com/usn/usn-602-1 cve-icon cve-icon
http://www.vupen.com/english/advisories/2008/1251/references cve-icon cve-icon
http://www.vupen.com/english/advisories/2008/1793/references cve-icon cve-icon
https://bugzilla.mozilla.org/show_bug.cgi?id=425576 cve-icon cve-icon
https://exchange.xforce.ibmcloud.com/vulnerabilities/41857 cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2008-1380 cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10752 cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2008-1380 cve-icon
https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00407.html cve-icon cve-icon
https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00463.html cve-icon cve-icon
https://www.redhat.com/archives/fedora-package-announce/2008-May/msg00058.html cve-icon cve-icon
https://www.redhat.com/archives/fedora-package-announce/2008-May/msg00074.html cve-icon cve-icon
History

No history.

Subscriptions

Mozilla Firefox Seamonkey Thunderbird
Redhat Enterprise Linux
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2024-08-07T08:17:34.702Z

Reserved: 2008-03-18T00:00:00.000Z

Link: CVE-2008-1380

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2008-04-17T19:05:00.000

Modified: 2026-04-23T00:35:47.467

Link: CVE-2008-1380

cve-icon Redhat

Severity : Critical

Publid Date: 2008-04-16T00:00:00Z

Links: CVE-2008-1380 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses