CVE-2008-3444: Input Validation
The content layout component in Mozilla Firefox 3.0 and 3.0.1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted but well-formed web page that contains "a simple set of legitimate HTML tags."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-3444?
CVE-2008-3444 is classified as a low severity vulnerability that can cause denial of service by crashing the Mozilla Firefox browser.
How do I fix CVE-2008-3444?
The best way to fix CVE-2008-3444 is to update Mozilla Firefox to version 3.0.2 or later.
What versions of Mozilla Firefox are affected by CVE-2008-3444?
CVE-2008-3444 affects Mozilla Firefox versions 3.0 and 3.0.1.
How does CVE-2008-3444 exploit a vulnerability?
CVE-2008-3444 can be exploited through a crafted web page that leads to a NULL pointer dereference, causing the application to crash.
Can CVE-2008-3444 be exploited remotely?
Yes, CVE-2008-3444 can be exploited by remote attackers through specially designed web pages.