First published: Fri Feb 08 2008(Updated: )
Mozilla Firefox before 2.0.0.12 and SeaMonkey before 1.1.8 allows remote attackers to steal navigation history and cause a denial of service (crash) via images in a page that uses designMode frames, which triggers memory corruption related to resize handles.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla SeaMonkey | <=1.1.7 | |
Mozilla Firefox | <=2.0.0.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-0419 is classified as a high-severity vulnerability due to its potential to allow remote attackers to steal navigation history and cause crashes.
To fix CVE-2008-0419, update Mozilla Firefox to version 2.0.0.12 or higher, or update SeaMonkey to version 1.1.8 or higher.
CVE-2008-0419 affects Mozilla Firefox versions prior to 2.0.0.12 and SeaMonkey versions prior to 1.1.8.
CVE-2008-0419 enables remote attackers to execute denial of service attacks by exploiting memory corruption vulnerabilities.
Yes, there are known attack vectors for CVE-2008-0419 that exploit designMode frames to compromise browser security.