Mozilla Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 do not properly change the source URI when processing a canvas element and an HTTP redirect, which allows remote attackers to bypass the same origin policy and access arbitrary images that are not directly accessible to the attacker. NOTE: this issue can be leveraged to enumerate software on the client by performing redirections related to moz-icon.
CVSS Details
- CVSS 3.1 Base Score: 4.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade seamonkeyUpgrade seamonkey-nssUpgrade seamonkey-chatUpgrade thunderbirdUpgrade seamonkey-dom-inspectorUpgrade seamonkey-develUpgrade seamonkey-nsprUpgrade seamonkey-nspr-develUpgrade seamonkey-js-debuggerUpgrade seamonkey-nss-develUpgrade seamonkey-mail | Dec 1, 2016 | Nov 13, 2008 |
| Freebsd | — | Upgrade linux-thunderbirdUpgrade thunderbirdUpgrade firefoxUpgrade linux-seamonkeyUpgrade seamonkeyUpgrade linux-firefox | Dec 10, 2025 | Nov 13, 2008 |
| Gentoo Linux | — | Upgrade www-client/mozilla-firefox.Upgrade net-libs/xulrunner.Upgrade net-libs/xulrunner-bin.Upgrade www-client/mozilla-firefox-bin.Upgrade dev-libs/nss.Upgrade mail-client/thunderbird-bin.Upgrade mail-client/mozilla-thunderbird-bin.Upgrade mail-client/mozilla-thunderbird.Upgrade www-client/firefox-bin.Upgrade www-client/icecat.Upgrade mail-client/thunderbird.Upgrade www-client/firefox.Upgrade www-client/seamonkey.Upgrade www-client/seamonkey-bin. | Oct 30, 2017 | Nov 13, 2008 |
| Mfsa2008 48 | — | Upgrade to Mozilla Firefox version 2.0.0.18 | Jun 14, 2012 | Nov 13, 2008 |
| Mozilla Seamonkey | — | Upgrade to Mozilla SeaMonkey version 1.1.13 | Feb 3, 2012 | Nov 13, 2008 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 2.0.0.18 | Feb 22, 2012 | Nov 13, 2008 |
| Suse | — | Upgrade mozilla-xulrunner181-32bitUpgrade mozilla-xulrunner181Upgrade mozilla-xulrunner190-translations-32bitUpgrade seamonkey-mailUpgrade mozilla-xulrunner190-gnomevfsUpgrade MozillaThunderbird-translationsUpgrade mozilla-xulrunner190-translationsUpgrade seamonkey-ircUpgrade mozilla-xulrunner190-develUpgrade mozilla-xulrunner190-translations-64bitUpgrade suse-releaseUpgrade mozilla-csUpgrade MozillaThunderbird-develUpgrade seamonkeyUpgrade mozilla-ircUpgrade mozilla-mailUpgrade epiphany-docUpgrade seamonkey-spellcheckerUpgrade mozilla-develUpgrade seamonkey-venkmanUpgrade epiphanyUpgrade mozilla-xulrunner190-gnomevfs-64bitUpgrade MozillaThunderbirdUpgrade mozilla-xulrunner190Upgrade mozilla-xulrunner190-32bitUpgrade mozilla-venkmanUpgrade mozillaUpgrade mozilla-huUpgrade epiphany-develUpgrade epiphany-extensionsUpgrade mozilla-xulrunner181-l10nUpgrade mozilla-xulrunner181-develUpgrade MozillaFirefox-translationsUpgrade gecko-sdkUpgrade mozilla-calendarUpgrade mozilla-xulrunner181-64bitUpgrade mozilla-deatUpgrade mozilla-dom-inspectorUpgrade seamonkey-dom-inspectorUpgrade mozilla-xulrunner190-64bitUpgrade MozillaFirefoxUpgrade mozilla-xulrunner190-gnomevfs-32bit | Feb 17, 2015 | Nov 13, 2008 |
| Ubuntu | — | Upgrade xulrunner-1.9Upgrade firefoxUpgrade thunderbirdUpgrade mozilla-thunderbirdUpgrade abrowserUpgrade firefox-3.0 | Nov 8, 2024 | Nov 13, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub