CVE-2008-5021

Mozilla Firefox < 2.0.0.18 - Race Condition

Title source: rule

Description

nsFrameManager in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by modifying properties of a file input element while it is still being initialized, then using the blur method to access uninitialized memory.

References (38)

... and 18 more

Scores

EPSS 0.2526
EPSS Percentile 96.1%

Classification

CWE
CWE-362
Status draft

Affected Products (21)

mozilla/firefox < 2.0.0.18
mozilla/seamonkey < 1.1.13
mozilla/thunderbird < 2.0.0.18
debian/debian_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
fedoraproject/fedora
fedoraproject/fedora
suse/linux_enterprise_debuginfo
novell/linux_desktop
novell/open_enterprise_server
opensuse/opensuse
opensuse/opensuse
... and 6 more

Timeline

Published Nov 13, 2008
Tracked Since Feb 18, 2026