CVE-2008-5018: Critical severity firefox vulnerability
The JavaScript engine in Mozilla Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) via vectors related to "insufficient class checking" in the Date class.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-5018?
CVE-2008-5018 has a medium severity level due to its potential to cause denial of service by crashing the affected applications.
How do I fix CVE-2008-5018?
To mitigate CVE-2008-5018, upgrade to the latest version of Mozilla Firefox, Thunderbird, or SeaMonkey that is not affected.
Which software is affected by CVE-2008-5018?
CVE-2008-5018 affects Mozilla Firefox 3.x before 3.0.4, 2.x before 2.0.0.18, Mozilla Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13.
What type of vulnerability is CVE-2008-5018?
CVE-2008-5018 is a denial of service vulnerability related to insufficient class checking in the JavaScript engine.
Is CVE-2008-5018 exploitable remotely?
Yes, CVE-2008-5018 can be exploited remotely, allowing attackers to crash the application by sending specially crafted input.