8.8
CVSSv3

CVE-2008-2934

Published: 18/07/2008 Updated: 08/02/2024
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Mozilla Firefox 3 prior to 3.0.1 on Mac OS X allows remote malicious users to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted GIF file that triggers a free of an uninitialized pointer.

Vulnerable Product Search on Vulmon Subscribe to Product

apple mac_os_x

canonical ubuntu linux 8.04

Vendor Advisories

A flaw was discovered in the browser engine A variable could be made to overflow causing the browser to crash If a user were tricked into opening a malicious web page, an attacker could cause a denial of service or possibly execute arbitrary code with the privileges of the user invoking the program (CVE-2008-2785) ...
Mozilla Foundation Security Advisory 2008-36 Crash with malformed GIF file on Mac OS X Announced July 16, 2008 Reporter Drew Yao Impact Critical Products Firefox Fixed in Firefox 3 ...