Lucene search

K
freebsdFreeBSD67BD39BA-12B5-11DD-BAB7-0016179B2DD5
HistoryApr 16, 2008 - 12:00 a.m.

firefox -- javascript garbage collector vulnerability

2008-04-1600:00:00
vuxml.freebsd.org
13

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS

0.461

Percentile

97.5%

Mozilla Foundation reports:

Fixes for security problems in the JavaScript engine described in
MFSA 2008-15 introduced a stability problem, where some users
experienced crashes during JavaScript garbage collection. This is
being fixed primarily to address stability concerns. We have no
demonstration that this particular crash is exploitable but are
issuing this advisory because some crashes of this type have been
shown to be exploitable in the past.

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS

0.461

Percentile

97.5%