CVE-2008-1380: Critical severity firefox vulnerability
The JavaScript engine in Mozilla Firefox before 2.0.0.14, Thunderbird before 2.0.0.14, and SeaMonkey before 1.1.10 allows remote attackers to cause a denial of service (garbage collector crash) and possibly have other impacts via a crafted web page. NOTE: this is due to an incorrect fix for CVE-2008-1237.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-1380?
CVE-2008-1380 has a severity rating that can lead to denial of service due to a crash in the JavaScript engine.
How do I fix CVE-2008-1380?
You can fix CVE-2008-1380 by updating to a version of Mozilla Firefox, Thunderbird, or SeaMonkey that is 2.0.0.14 or later.
What versions are affected by CVE-2008-1380?
CVE-2008-1380 affects Firefox versions prior to 2.0.0.14, Thunderbird versions before 2.0.0.14, and SeaMonkey versions before 1.1.10.
What type of attack is CVE-2008-1380 related to?
CVE-2008-1380 is related to a denial of service attack that can be triggered by a specially crafted web page.
Is CVE-2008-1380 a critical vulnerability?
While CVE-2008-1380 is not rated as critical, it can significantly disrupt service by crashing the application.