The browser engine in Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, Thunderbird before 3.0.2, and SeaMonkey before 2.0.3 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the nsBlockFrame::StealFrame function in layout/generic/nsBlockFrame.cpp, and unspecified other vectors.
CVSS Details
- CVSS 3.1 Base Score: 9.6
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade seamonkey-dom-inspectorUpgrade xulrunner-devel-unstableUpgrade xulrunner-develUpgrade seamonkey-nss-develUpgrade seamonkey-js-debuggerUpgrade seamonkeyUpgrade seamonkey-develUpgrade seamonkey-nssUpgrade seamonkey-mailUpgrade xulrunnerUpgrade seamonkey-nsprUpgrade seamonkey-nspr-develUpgrade seamonkey-chatUpgrade thunderbirdUpgrade firefox | Dec 1, 2016 | Feb 22, 2010 |
| Freebsd | — | Upgrade linux-firefoxUpgrade seamonkeyUpgrade thunderbirdUpgrade linux-firefox-develUpgrade firefox | Dec 10, 2025 | Feb 18, 2010 |
| Gentoo Linux | — | Upgrade net-libs/xulrunner-bin.Upgrade www-client/firefox-bin.Upgrade mail-client/thunderbird.Upgrade mail-client/mozilla-thunderbird-bin.Upgrade mail-client/thunderbird-bin.Upgrade www-client/mozilla-firefox-bin.Upgrade dev-libs/nss.Upgrade net-libs/xulrunner.Upgrade www-client/seamonkey-bin.Upgrade www-client/firefox.Upgrade www-client/icecat.Upgrade mail-client/mozilla-thunderbird.Upgrade www-client/mozilla-firefox.Upgrade www-client/seamonkey. | Oct 30, 2017 | Feb 22, 2010 |
| Mfsa2010 01 | — | Upgrade to Mozilla Firefox version 3.5.8Upgrade to Mozilla Firefox version 3.0.18Upgrade to Mozilla Firefox version 3.6 | Jun 14, 2012 | Feb 22, 2010 |
| Mozilla Seamonkey | — | Upgrade to Mozilla SeaMonkey version 2.0.3 | Feb 3, 2012 | Feb 22, 2010 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 3.0.2 | Feb 22, 2012 | Feb 22, 2010 |
| Oracle_linux | — | Upgrade xulrunner-devel-unstableUpgrade xulrunner-develUpgrade firefoxUpgrade xulrunner | Oct 16, 2024 | Feb 21, 2010 |
| Suse | — | Upgrade libidl-x86Upgrade MozillaThunderbird-develUpgrade MozillaFirefox-develUpgrade MozillaThunderbirdUpgrade mozilla-xulrunner192-x86Upgrade mozilla-xulrunner191-32bitUpgrade mozilla-xulrunner191-x86Upgrade mozilla-xulrunner190-x86Upgrade libfreebl3Upgrade libidl-32bitUpgrade gconf2-32bitUpgrade mozilla-xulrunner192Upgrade mozilla-nsprUpgrade libfreebl3-x86Upgrade mozilla-xulrunner192-gnomeUpgrade orbit2-x86Upgrade mozilla-nspr-32bitUpgrade MozillaThunderbird-translations-otherUpgrade mozilla-nssUpgrade MozillaFirefox-branding-SLEDUpgrade mozilla-nss-x86Upgrade gconf2-x86Upgrade mozilla-nss-toolsUpgrade mozilla-nspr-x86Upgrade mozilla-xulrunner190Upgrade mozilla-xulrunner192-32bitUpgrade MozillaFirefoxUpgrade mozilla-xulrunner190-32bitUpgrade mozilla-nss-32bitUpgrade MozillaThunderbird-translations-commonUpgrade libfreebl3-32bitUpgrade mozilla-xulrunner190-translationsUpgrade gconf2Upgrade mozilla-xulrunner191-translationsUpgrade libidlUpgrade mozilla-xulrunner191Upgrade orbit2-32bitUpgrade orbit2Upgrade mozilla-xulrunner190-gnomevfsUpgrade mozilla-xulrunner192-translationsUpgrade MozillaFirefox-translationsUpgrade mozilla-xulrunner191-gnomevfs | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade abrowserUpgrade xulrunner-1.9Upgrade firefox-3.0Upgrade xulrunner-1.9.1Upgrade firefox-3.5 | Nov 8, 2024 | Feb 22, 2010 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub