Multiple heap-based buffer overflows in Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allow remote attackers to cause a denial of service (application crash) or execute arbitrary code via (1) the "Send page" functionality, (2) certain responses from a malicious POP3 server, or (3) a link containing a non-ASCII hostname.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade thunderbirdUpgrade mozillaUpgrade firefoxUpgrade linux-mozillafirebirdUpgrade linux-mozillaUpgrade mozilla-gtk1 | Dec 10, 2025 | Sep 28, 2004 |
| Gentoo Linux | — | Upgrade www-client/mozilla-bin.Upgrade mail-client/mozilla-thunderbird.Upgrade www-client/mozilla-firefox-bin.Upgrade mail-client/mozilla-thunderbird-bin.Upgrade www-client/mozilla.Upgrade www-client/mozilla-firefox.Upgrade www-client/epiphany. | Oct 30, 2017 | Jan 27, 2005 |
| Suse | — | Upgrade mozilla-dom-inspectorUpgrade mozillaUpgrade mozilla-calendarUpgrade mozilla-ircUpgrade mozilla-mailUpgrade mozilla-venkman | Feb 17, 2015 | Jan 27, 2005 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub