Integer overflow in the MathML component in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via an mtd element with a large integer value in the rowspan attribute, related to the layout engine.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade firefoxUpgrade seamonkey-chatUpgrade thunderbirdUpgrade seamonkey-dom-inspectorUpgrade seamonkey-mailUpgrade seamonkeyUpgrade devhelpUpgrade devhelp-develUpgrade seamonkey-develUpgrade seamonkey-js-debugger | Dec 1, 2016 | Sep 24, 2008 |
| Freebsd | — | Upgrade flockUpgrade linux-flockUpgrade linux-thunderbirdUpgrade firefoxUpgrade linux-firefox-develUpgrade thunderbirdUpgrade linux-seamonkeyUpgrade seamonkeyUpgrade linux-firefoxUpgrade linux-seamonkey-devel | Dec 10, 2025 | Sep 24, 2008 |
| Gentoo Linux | — | Upgrade www-client/mozilla-firefox.Upgrade net-libs/xulrunner.Upgrade www-client/firefox.Upgrade www-client/seamonkey-bin.Upgrade www-client/seamonkey.Upgrade dev-libs/nss.Upgrade www-client/icecat.Upgrade mail-client/thunderbird.Upgrade mail-client/mozilla-thunderbird.Upgrade www-client/firefox-bin.Upgrade mail-client/thunderbird-bin.Upgrade net-libs/xulrunner-bin.Upgrade www-client/mozilla-firefox-bin.Upgrade mail-client/mozilla-thunderbird-bin. | Oct 30, 2017 | Sep 24, 2008 |
| Mfsa2008 42 | — | Upgrade to Mozilla Firefox version 3.0.2Upgrade to Mozilla Firefox version 2.0.0.17 | Jun 14, 2012 | Sep 24, 2008 |
| Mozilla Seamonkey | — | Upgrade to Mozilla SeaMonkey version 1.1.12 | Feb 3, 2012 | Sep 24, 2008 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 2.0.0.17 | Feb 22, 2012 | Sep 24, 2008 |
| Oracle_linux | — | Upgrade nss-toolsUpgrade xulrunnerUpgrade yelpUpgrade devhelp-develUpgrade firefoxUpgrade nss-pkcs11-develUpgrade xulrunner-develUpgrade xulrunner-devel-unstableUpgrade nssUpgrade devhelpUpgrade nss-devel | Oct 16, 2024 | Sep 24, 2008 |
| Suse | — | Upgrade mozilla-xulrunner190-translationsUpgrade mozillaUpgrade mozilla-dom-inspectorUpgrade seamonkey-venkmanUpgrade seamonkey-dom-inspectorUpgrade mozilla-xulrunner181-64bitUpgrade mozilla-xulrunner190-translations-64bitUpgrade seamonkeyUpgrade mozilla-xulrunner181Upgrade mozilla-xulrunner181-develUpgrade mozilla-xulrunner190-64bitUpgrade seamonkey-mailUpgrade mozilla-xulrunner190-gnomevfs-32bitUpgrade mozilla-xulrunner190-develUpgrade mozilla-xulrunner190-gnomevfsUpgrade gecko-sdkUpgrade MozillaThunderbird-translationsUpgrade MozillaThunderbird-develUpgrade mozilla-calendarUpgrade mozilla-develUpgrade mozilla-xulrunner190-32bitUpgrade MozillaFirefox-translationsUpgrade seamonkey-ircUpgrade mozilla-ircUpgrade mozilla-xulrunner190-translations-32bitUpgrade mozilla-xulrunner181-32bitUpgrade mozilla-xulrunner190-gnomevfs-64bitUpgrade mozilla-deatUpgrade mozilla-csUpgrade mozilla-xulrunner190Upgrade mozilla-mailUpgrade mozilla-huUpgrade suse-releaseUpgrade mozilla-venkmanUpgrade mozilla-xulrunner181-l10nUpgrade MozillaThunderbirdUpgrade MozillaFirefoxUpgrade seamonkey-spellchecker | Feb 17, 2015 | Sep 24, 2008 |
| Ubuntu | — | Upgrade thunderbirdUpgrade mozilla-thunderbirdUpgrade firefox-3.0Upgrade xulrunner-1.9Upgrade firefox | Nov 8, 2024 | Sep 24, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub