CVE-2008-4062
Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allow remote attackers to cause a denial of se...
Affects 5 products across 3 vendors.
Broad class covering failures in managing system resources such as memory, file handles, and connections.
This vulnerability was disclosed in 2008. A critical vulnerability affects Canonical systems (CVE-2008-4062). No public exploit code is currently available. Isolate affected systems if patching is not feasible.
BSID: BS-2008-GLOBAL-022114-C • Model: rule-based-v1 • Confidence: MEDIUM
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2008-4062?
What is the CVSS score for CVE-2008-4062?
Is CVE-2008-4062 actively exploited?
How do I remediate CVE-2008-4062?
What systems are affected by CVE-2008-4062?
| CVE ID | CVE-2008-4062 |
|---|---|
| BSID | BS-2008-GLOBAL-022114-C BreachSpider Global ID |
| CVSS Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
| Published | 2008-09-24 |
| Last Modified | 2026-04-23 |
| ICS Relevance | 0% |
| Weakness (CWE) | |
| Source | NVD |
Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the JavaScript engine and (1) misinterpretation of the characteristics of Namespace and QName in jsxml.c, (2) misuse of signed integers in the nsEscapeCount function in nsEscape.cpp, and (3) interaction of JavaScript garbage collection with certain use of an NPObject in the nsNPObjWrapper::GetNewOrUsed function in nsJSNPRuntime.cpp.
Source: NIST NVD / MITRE CVE Database
Vulnerability details: Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the JavaScript engine and (1) misinterpretation of the characteristics of Namespace and QName in jsxml.c, (2) misuse of signed integers in the nsEscapeCount function in nsEscape.cpp, and (3) intera CVSS vector: AV:N/AC:L/Au:N/C:C/I:C/A:C.
Exploitation Likelihood: LOW
| Vendor | Product | Fixed Version |
|---|---|---|
| Canonical | Ubuntu Linux | — |
| Debian | Debian Linux | — |
| Mozilla | Firefox | — |
| Mozilla | Thunderbird | — |
| Mozilla | Seamonkey | — |
| CISA KEV | Not in KEV catalog |
|---|---|
| Public Exploit | Not confirmed |
| PoC Code | Not confirmed |
SAGE Enrichment Record — provenance & audit hash
| Model | rule-based-v1 |
|---|---|
| Confidence | MEDIUM |
| Enriched At | 2026-05-24 |
| SHA-512 Audit Hash | 88b040bec1a7058d6ba257e601a576a9a4fc1ccf970bea02424cd7e1bbc5a5e555d4b224a85d9e1b5293f2dd8ae84b1eb91562173a9d5474d83d2274e94ba583 |
Critical Severity - Know Your Exposure
A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.
Check Your Assets Free →