Unspecified vulnerability in Firefox and Thunderbird 1.5 before 1.5.0.2, and SeaMonkey before 1.0.1, allows remote attackers to bypass the js_ValueToFunctionObject check and execute arbitrary code via unknown vectors involving setTimeout and Firefox' ForEach method.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade thunderbird | Jul 30, 2024 | Apr 14, 2006 |
| Freebsd | — | Upgrade linux-firefoxUpgrade seamonkeyUpgrade mozillaUpgrade linux-mozilla-develUpgrade linux-mozillaUpgrade linux-seamonkeyUpgrade thunderbirdUpgrade firefoxUpgrade mozilla-thunderbird | Dec 10, 2025 | Apr 16, 2006 |
| Mfsa2006 28 | — | Upgrade to Mozilla Firefox version 1.5.0.2 | Nov 21, 2013 | Apr 14, 2006 |
| Mozilla Seamonkey | — | Upgrade to Mozilla SeaMonkey version 1.0.1 | Nov 21, 2013 | Apr 14, 2006 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 1.5.0.2 | Nov 21, 2013 | Apr 14, 2006 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub