The JavaScript engine in Mozilla Firefox before 2.0.0.14, Thunderbird before 2.0.0.14, and SeaMonkey before 1.1.10 allows remote attackers to cause a denial of service (garbage collector crash) and possibly have other impacts via a crafted web page. NOTE: this is due to an incorrect fix for CVE-2008-1237.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade linux-seamonkey-develUpgrade linux-firefoxUpgrade linux-thunderbirdUpgrade linux-flockUpgrade seamonkeyUpgrade thunderbirdUpgrade linux-seamonkeyUpgrade linux-firefox-develUpgrade flockUpgrade firefox | Dec 10, 2025 | Apr 25, 2008 |
| Gentoo Linux | — | Upgrade www-client/mozilla-firefox-bin.Upgrade net-libs/xulrunner-bin.Upgrade mail-client/mozilla-thunderbird-bin.Upgrade www-client/mozilla-firefox.Upgrade net-libs/xulrunner.Upgrade www-client/seamonkey-bin.Upgrade mail-client/mozilla-thunderbird.Upgrade www-client/seamonkey. | Oct 30, 2017 | Apr 17, 2008 |
| Mfsa2008 20 | — | Upgrade to Mozilla Firefox version 2.0.0.14 | Jun 14, 2012 | Apr 17, 2008 |
| Mozilla Seamonkey | — | Upgrade to Mozilla SeaMonkey version 1.1.10 | Feb 3, 2012 | Apr 17, 2008 |
| Oracle_linux | — | Upgrade firefox-develUpgrade firefox | Oct 16, 2024 | Apr 17, 2008 |
| Suse | — | Upgrade mozilla-xulrunner181Upgrade epiphany-docUpgrade suse-releaseUpgrade MozillaThunderbirdUpgrade MozillaThunderbird-translationsUpgrade epiphanyUpgrade mozilla-xulrunner181-l10nUpgrade MozillaFirefoxUpgrade epiphany-extensionsUpgrade mozilla-xulrunner181-32bitUpgrade mozilla-xulrunner181-develUpgrade epiphany-develUpgrade MozillaFirefox-translationsUpgrade mozilla-xulrunner181-64bit | Feb 17, 2015 | Apr 17, 2008 |
| Ubuntu | — | Upgrade firefox | Nov 8, 2024 | Apr 17, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub