mozilla: CSS reference counter overflow (ZDI-CAN-349)
Published Jun 19, 2008
9.3
HIGHCVSS 2.0
EPSS 5.28%
Description
Mozilla Firefox before 2.0.0.16 and 3.x before 3.0.1, Thunderbird before 2.0.0.16, and SeaMonkey before 1.1.11 use an incorrect integer data type as a CSS object reference counter in the CSSValue array (aka nsCSSValue:Array) data structure, which allows remote attackers to execute arbitrary code via a large number of references to a common CSS object, leading to a counter overflow and a free of in-use memory, aka ZDI-CAN-349.
Affected products
No data.
- ≤ 2.0.0.15
- 2.0
- 2.0.0.1
- 2.0.0.2
- 2.0.0.3
- 2.0.0.4
- 2.0.0.5
- 2.0.0.6
- 2.0.0.7
- 2.0.0.8
- 2.0.0.9
- 2.0.0.10
- 2.0.0.11
- 2.0.0.12
- 2.0.0.13
- 2.0.0.14
- 3.0
- ≤ 1.1.10
- 1.0
- 1.0
- 1.0
- 1.0.1
- 1.0.2
- 1.0.3
- 1.0.4
- 1.0.5
- 1.0.6
- 1.0.7
- 1.0.8
- 1.0.9
- 1.1
- 1.1
- 1.1
- 1.1.1
- 1.1.2
- 1.1.3
- 1.1.4
- 1.1.5
- 1.1.6
- 1.1.7
- 1.1.8
- 1.1.9
- ≤ 2.0.0.14
- 0.1
- 0.2
- 0.3
- 0.4
- 0.5
- 0.6
- 0.7
- 0.8
- 0.9
- 1.0
- 1.0.2
- 1.0.5
- 1.0.6
- 1.0.7
- 1.0.8
- 1.5
- 1.5.0.2
- 1.5.0.4
- 1.5.0.5
- 1.5.0.7
- 1.5.0.8
- 1.5.0.9
- 1.5.0.10
- 1.5.0.12
- 1.5.0.13
- 1.5.0.14
- 2.0.0.0
- 2.0.0.4
- 2.0.0.5
- 2.0.0.6
- 2.0.0.9
- 2.0.0.12
No data.
Red Hat Enterprise Linux 2.1
seamonkey-0:1.0.9-0.18.el2
Fixed · RHSA-2008:0599
Red Hat Enterprise Linux 3
seamonkey-0:1.0.9-0.22.el3
Fixed · RHSA-2008:0599
Red Hat Enterprise Linux 4
devhelp-0:0.10-0.8.1.el4
Fixed · RHSA-2008:0599
Red Hat Enterprise Linux 4
firefox-0:1.5.0.12-0.21.el4
Fixed · RHSA-2008:0598
Red Hat Enterprise Linux 4
seamonkey-0:1.0.9-16.4.el4_6
Fixed · RHSA-2008:0599
Red Hat Enterprise Linux 4
thunderbird-0:1.5.0.12-14.el4
Fixed · RHSA-2008:0616
Red Hat Enterprise Linux 4.5 Z Stream
firefox-0:1.5.0.12-0.21.el4
Fixed · RHSA-2008:0598
Red Hat Enterprise Linux 5
devhelp-0:0.12-18.el5
Fixed · RHSA-2008:0597
Red Hat Enterprise Linux 5
firefox-0:3.0.1-1.el5
Fixed · RHSA-2008:0597
Red Hat Enterprise Linux 5
nspluginwrapper-0:0.9.91.5-22.el5
Fixed · RHSA-2008:0597
Red Hat Enterprise Linux 5
thunderbird-0:2.0.0.16-1.el5
Fixed · RHSA-2008:0616
Red Hat Enterprise Linux 5
xulrunner-0:1.9.0.1-1.el5
Fixed · RHSA-2008:0597
Red Hat Enterprise Linux 5
yelp-0:2.16.0-20.el5
Fixed · RHSA-2008:0597
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 2.1 | seamonkey-0:1.0.9-0.18.el2 | Fixed | RHSA-2008:0599 |
| Red Hat Enterprise Linux 3 | seamonkey-0:1.0.9-0.22.el3 | Fixed | RHSA-2008:0599 |
| Red Hat Enterprise Linux 4 | devhelp-0:0.10-0.8.1.el4 | Fixed | RHSA-2008:0599 |
| Red Hat Enterprise Linux 4 | firefox-0:1.5.0.12-0.21.el4 | Fixed | RHSA-2008:0598 |
| Red Hat Enterprise Linux 4 | seamonkey-0:1.0.9-16.4.el4_6 | Fixed | RHSA-2008:0599 |
| Red Hat Enterprise Linux 4 | thunderbird-0:1.5.0.12-14.el4 | Fixed | RHSA-2008:0616 |
| Red Hat Enterprise Linux 4.5 Z Stream | firefox-0:1.5.0.12-0.21.el4 | Fixed | RHSA-2008:0598 |
| Red Hat Enterprise Linux 5 | devhelp-0:0.12-18.el5 | Fixed | RHSA-2008:0597 |
| Red Hat Enterprise Linux 5 | firefox-0:3.0.1-1.el5 | Fixed | RHSA-2008:0597 |
| Red Hat Enterprise Linux 5 | nspluginwrapper-0:0.9.91.5-22.el5 | Fixed | RHSA-2008:0597 |
| Red Hat Enterprise Linux 5 | thunderbird-0:2.0.0.16-1.el5 | Fixed | RHSA-2008:0616 |
| Red Hat Enterprise Linux 5 | xulrunner-0:1.9.0.1-1.el5 | Fixed | RHSA-2008:0597 |
| Red Hat Enterprise Linux 5 | yelp-0:2.16.0-20.el5 | Fixed | RHSA-2008:0597 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:M/Au:N/C:C/I:C/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (14 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 5.28% (0.05284) | 92.32th | v5 (v2026.06.15) |
| Jun 15, 2026 | 5.28% (0.05284) | 91.49th | v5 (v2026.06.15) |
| Mar 17, 2025 | 9.52% (0.09520) | 92.26th | v4 (v2025.03.14) |
| Mar 16, 2025 | 44.13% (0.44126) | 97.53th | v3 (v2023.03.01) |
| Feb 6, 2025 | 41.22% (0.41223) | 97.40th | v3 (v2023.03.01) |
| Dec 30, 2024 | 28.30% (0.28303) | 96.84th | v3 (v2023.03.01) |
| Dec 17, 2024 | 39.12% (0.39124) | 97.27th | v3 (v2023.03.01) |
| Nov 21, 2024 | 54.87% (0.54875) | 97.74th | v3 (v2023.03.01) |
| Oct 14, 2024 | 41.34% (0.41342) | 97.37th | v3 (v2023.03.01) |
| Jun 25, 2024 | 45.24% (0.45236) | 97.43th | v3 (v2023.03.01) |
| Mar 7, 2023 | 43.47% (0.43474) | 96.74th | v3 (v2023.03.01) |
| Mar 6, 2023 | 9.92% (0.09915) | 94.52th | v2 (v2022.01.01) |
| Apr 1, 2022 | 9.92% (0.09915) | 94.04th | v2 (v2022.01.01) |
| Feb 4, 2022 | 9.92% (0.09915) | 87.53th | v2 (v2022.01.01) |
References (64)
- http://blog.mozilla.com/security/2008/06/18/new-security-issue-under-investigation/ x_refsource_MISC
- http://dvlabs.tippingpoint.com/blog/2008/06/18/vulnerability-in-mozilla-firefox-30 x_refsource_MISC
- http://rhn.redhat.com/errata/RHSA-2008-0616.html vendor-advisoryx_refsource_REDHAT
- http://secunia.com/advisories/30761 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/31121 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/31122 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/31129 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/31144 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/31145 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/31154 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/31157 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/31176 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/31183 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/31195 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/31220 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/31253 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/31261 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/31270 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/31286 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/31306 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/31377 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/31403 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/33433 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/34501 third-party-advisoryx_refsource_SECUNIA
- http://security.gentoo.org/glsa/glsa-200808-03.xml vendor-advisoryx_refsource_GENTOO
- http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.410484 vendor-advisoryx_refsource_SLACKWARE
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-256408-1 vendor-advisoryx_refsource_SUNALERT
- http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0238 x_refsource_CONFIRM
- http://www.debian.org/security/2008/dsa-1614 vendor-advisoryx_refsource_DEBIAN
- http://www.debian.org/security/2008/dsa-1615 vendor-advisoryx_refsource_DEBIAN
- http://www.debian.org/security/2008/dsa-1621 vendor-advisoryx_refsource_DEBIAN
- http://www.debian.org/security/2009/dsa-1697 vendor-advisoryx_refsource_DEBIAN
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:148 vendor-advisoryx_refsource_MANDRIVA
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:155 vendor-advisoryx_refsource_MANDRIVA
- http://www.mozilla.org/security/announce/2008/mfsa2008-34.html x_refsource_CONFIRMPatchVendor Advisory
- http://www.novell.com/support/search.do?cmd=displayKC&docType=kc&externalId=InfoDocument-patchbuilder-readme5031400 x_refsource_CONFIRM
- http://www.redhat.com/support/errata/RHSA-2008-0597.html vendor-advisoryx_refsource_REDHAT
- http://www.redhat.com/support/errata/RHSA-2008-0598.html vendor-advisoryx_refsource_REDHAT
- http://www.redhat.com/support/errata/RHSA-2008-0599.html vendor-advisoryx_refsource_REDHAT
- http://www.securityfocus.com/archive/1/494504/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/archive/1/494860/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/bid/29802 vdb-entryx_refsource_BID
- http://www.securitytracker.com/id?1020336 vdb-entryx_refsource_SECTRACK
- http://www.slackware.org/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.380767 vendor-advisoryx_refsource_SLACKWARE
- http://www.slackware.org/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.380974 vendor-advisoryx_refsource_SLACKWARE
- http://www.ubuntu.com/usn/usn-623-1 vendor-advisoryx_refsource_UBUNTU
- http://www.ubuntu.com/usn/usn-626-1 vendor-advisoryx_refsource_UBUNTU
- http://www.ubuntu.com/usn/usn-626-2 vendor-advisoryx_refsource_UBUNTU
- http://www.ubuntu.com/usn/usn-629-1 vendor-advisoryx_refsource_UBUNTU
- http://www.vupen.com/english/advisories/2008/1873 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2009/0977 vdb-entryx_refsource_VUPEN
- http://www.zerodayinitiative.com/advisories/ZDI-08-044/ x_refsource_MISC
- https://access.redhat.com/security/cve/CVE-2008-2785 Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=440230 x_refsource_CONFIRM
- https://bugzilla.redhat.com/show_bug.cgi?id=452204 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43167 vdb-entryx_refsource_XF
- https://issues.rpath.com/browse/RPL-2683 x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2008-2785
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9900 vdb-entrysignaturex_refsource_OVAL
- https://www.cve.org/CVERecord?id=CVE-2008-2785
- https://www.redhat.com/archives/fedora-package-announce/2008-August/msg00125.html vendor-advisoryx_refsource_FEDORA
- https://www.redhat.com/archives/fedora-package-announce/2008-August/msg00144.html vendor-advisoryx_refsource_FEDORA
- https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00667.html vendor-advisoryx_refsource_FEDORA
- https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00672.html vendor-advisoryx_refsource_FEDORA
Change history (0)
No recorded changes yet.