CVE-2008-4062

CRITICAL

Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allow remote attackers to cause a denial of se...

Affects 5 products across 3 vendors.

BCS7.73
CVSS 2.010.0
EPSS5.0%
Percentile91th
PatchPatched
CVSS Vector — Plain English Remotely exploitable over the network, low complexity.
CWE Weakness Definitions
CWE-399: Resource Management Errors

Broad class covering failures in managing system resources such as memory, file handles, and connections.

◆ SAGE Intelligence — CITED Relevance Research Team

This vulnerability was disclosed in 2008. A critical vulnerability affects Canonical systems (CVE-2008-4062). No public exploit code is currently available. Isolate affected systems if patching is not feasible.

BSID: BS-2008-GLOBAL-022114-C • Model: rule-based-v1 • Confidence: MEDIUM

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2008-4062?
This vulnerability was disclosed in 2008. A critical vulnerability affects Canonical systems (CVE-2008-4062). No public exploit code is currently available. Isolate affected systems if patching is not feasible.
What is the CVSS score for CVE-2008-4062?
CVE-2008-4062 has CVSS 10.0 (Critical). Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C. EPSS: 5.0%.
Is CVE-2008-4062 actively exploited?
No confirmed active exploitation of CVE-2008-4062 as of 2026-05-30.
How do I remediate CVE-2008-4062?
Priority: MEDIUM. Advisory: http://www.mozilla.org/security/announce/2008/mfsa2008-42.html PSIRT: [email protected]
What systems are affected by CVE-2008-4062?
CVE-2008-4062 affects: Canonical, Debian, Mozilla, Mozilla, Mozilla.
Vulnerability Details
CVE IDCVE-2008-4062
BSIDBS-2008-GLOBAL-022114-C BreachSpider Global ID
CVSS VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Published2008-09-24
Last Modified2026-04-23
ICS Relevance0%
Weakness (CWE)
SourceNVD
Official Description

Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the JavaScript engine and (1) misinterpretation of the characteristics of Namespace and QName in jsxml.c, (2) misuse of signed integers in the nsEscapeCount function in nsEscape.cpp, and (3) interaction of JavaScript garbage collection with certain use of an NPObject in the nsNPObjWrapper::GetNewOrUsed function in nsJSNPRuntime.cpp.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

Vulnerability details: Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the JavaScript engine and (1) misinterpretation of the characteristics of Namespace and QName in jsxml.c, (2) misuse of signed integers in the nsEscapeCount function in nsEscape.cpp, and (3) intera CVSS vector: AV:N/AC:L/Au:N/C:C/I:C/A:C.

Exploitation Likelihood: LOW

Affected Products
VendorProductFixed Version
Canonical Ubuntu Linux
Debian Debian Linux
Mozilla Firefox
Mozilla Thunderbird
Mozilla Seamonkey
Remediation
View Vendor Advisory →

Remediation Priority: MEDIUM

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: August 2026 | Threat Age: 6522 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Modelrule-based-v1
ConfidenceMEDIUM
Enriched At2026-05-24
SHA-512 Audit Hash88b040bec1a7058d6ba257e601a576a9a4fc1ccf970bea02424cd7e1bbc5a5e555d4b224a85d9e1b5293f2dd8ae84b1eb91562173a9d5474d83d2274e94ba583
Related CVEs affecting Canonical
CVE-2004-1018 10.0 Multiple integer handling errors in PHP before 4.3.10 allow attackers to bypa... CVE-2014-0457 10.0 Unspecified vulnerability in Oracle Java SE 5.0u61, SE 6u71, 7u51, and 8; JRo... CVE-2007-0063 10.0 Integer underflow in the DHCP server in EMC VMware Workstation before 5.5.5 B... CVE-2014-0429 10.0 Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JRocki... CVE-2004-1063 10.0 PHP 4.x to 4.3.9, and PHP 5.x to 5.0.2, when running in safe mode on a multit...
View all Canonical CVEs →

Critical Severity - Know Your Exposure

A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →