The browser engine in Mozilla Firefox 3.x before 3.0.9, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.16 allows remote attackers to cause a denial of service (application crash) and possibly trigger memory corruption via vectors related to (1) nsAsyncInstantiateEvent::Run, (2) nsStyleContext::Destroy, (3) nsComputedDOMStyle::GetWidth, (4) the xslt_attributeset_ImportSameName.html test case for the XSLT stylesheet compiler, (5) nsXULDocument::SynchronizeBroadcastListener, (6) IsBindingAncestor, (7) PL_DHashTableOperate and nsEditor::EndUpdateViewBatch, and (8) gfxSkipCharsIterator::SetOffsets, and other vectors.
CVSS Details
- CVSS 3.1 Base Score: 4.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade firefoxUpgrade xulrunner-develUpgrade xulrunnerUpgrade xulrunner-devel-unstable | Dec 1, 2016 | Apr 22, 2009 |
| Freebsd | — | Upgrade linux-thunderbirdUpgrade linux-firefox-develUpgrade linux-seamonkeyUpgrade seamonkeyUpgrade firefoxUpgrade linux-firefoxUpgrade thunderbirdUpgrade linux-seamonkey-devel | Dec 10, 2025 | Apr 22, 2009 |
| Gentoo Linux | — | Upgrade www-client/firefox.Upgrade net-libs/xulrunner-bin.Upgrade mail-client/mozilla-thunderbird.Upgrade www-client/seamonkey.Upgrade mail-client/thunderbird-bin.Upgrade mail-client/thunderbird.Upgrade www-client/icecat.Upgrade www-client/firefox-bin.Upgrade net-libs/xulrunner.Upgrade www-client/mozilla-firefox.Upgrade www-client/seamonkey-bin.Upgrade dev-libs/nss.Upgrade mail-client/mozilla-thunderbird-bin.Upgrade www-client/mozilla-firefox-bin. | Oct 30, 2017 | Apr 22, 2009 |
| Mfsa2009 14 | — | Upgrade to Mozilla Firefox version 3.0.9 | Jun 14, 2012 | Apr 22, 2009 |
| Mozilla Seamonkey | — | Upgrade to Mozilla SeaMonkey version 1.1.16 | Feb 3, 2012 | Apr 22, 2009 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 2.0.0.22 | Feb 22, 2012 | Apr 22, 2009 |
| Oracle_linux | — | Upgrade xulrunner-develUpgrade xulrunnerUpgrade xulrunner-devel-unstableUpgrade firefox | Oct 16, 2024 | Apr 22, 2009 |
| Suse | — | Upgrade mozilla-xulrunner191-gnomevfsUpgrade MozillaFirefox-translations-otherUpgrade mozilla-nss-x86Upgrade mozilla-xulrunner191-32bitUpgrade mozilla-xulrunner191Upgrade orbit2-32bitUpgrade orbit2Upgrade mozilla-xulrunner191-translationsUpgrade libidl-x86Upgrade mozilla-xulrunner190-translationsUpgrade gconf2Upgrade mozilla-xulrunner190-gnomevfsUpgrade mozilla-xulrunner192-32bitUpgrade libidlUpgrade mozilla-nspr-32bitUpgrade MozillaFirefoxUpgrade mozilla-xulrunner192-gnomeUpgrade mozilla-nss-32bitUpgrade mozilla-nss-toolsUpgrade mozilla-xulrunner192-translationsUpgrade mozilla-xulrunner191-x86Upgrade mozilla-xulrunner190-x86Upgrade mozilla-nssUpgrade mozilla-xulrunner192Upgrade libidl-32bitUpgrade MozillaFirefox-translationsUpgrade MozillaFirefox-translations-commonUpgrade MozillaFirefox-branding-SLEDUpgrade gconf2-32bitUpgrade mozilla-xulrunner190-32bitUpgrade orbit2-x86Upgrade MozillaFirefox-develUpgrade mozilla-nspr-x86Upgrade mozilla-xulrunner192-x86Upgrade mozilla-nsprUpgrade mozilla-xulrunner190Upgrade gconf2-x86Upgrade libfreebl3Upgrade libfreebl3-32bitUpgrade libfreebl3-x86 | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade xulrunner-1.9Upgrade abrowserUpgrade firefox-3.0 | Nov 8, 2024 | Apr 22, 2009 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub