Mozilla Firefox 1.5 before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via simultaneous XPCOM events, which causes a timer object to be deleted in a way that triggers memory corruption.
CVSS Details
- CVSS 3.1 Base Score: 8.4
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade thunderbird | Jul 30, 2024 | Jul 27, 2006 |
| Freebsd | — | Upgrade linux-mozilla-develUpgrade firefoxUpgrade linux-firefox-develUpgrade mozillaUpgrade seamonkeyUpgrade mozilla-thunderbirdUpgrade linux-mozillaUpgrade linux-seamonkeyUpgrade thunderbirdUpgrade linux-thunderbirdUpgrade linux-firefox | Dec 10, 2025 | Jul 27, 2006 |
| Gentoo Linux | — | Upgrade mail-client/mozilla-thunderbird-bin.Upgrade www-client/mozilla-firefox-bin.Upgrade mail-client/mozilla-thunderbird.Upgrade www-client/seamonkey.Upgrade www-client/mozilla-firefox. | Oct 30, 2017 | Jul 27, 2006 |
| Mfsa2006 46 | — | Upgrade to Mozilla Firefox version 1.5.0.5Upgrade to the latest version of Mozilla Firefox | Jul 25, 2006 | Jul 25, 2006 |
| Ubuntu | — | Upgrade mozilla-thunderbird-locale-itUpgrade mozilla-thunderbird-locale-ukUpgrade mozilla-thunderbird-enigmailUpgrade mozilla-thunderbird-typeaheadfindUpgrade firefoxUpgrade mozilla-thunderbird-locale-nlUpgrade mozilla-thunderbird-locale-deUpgrade mozilla-thunderbird-locale-caUpgrade mozilla-thunderbird-locale-frUpgrade mozilla-thunderbirdUpgrade mozilla-thunderbird-inspectorUpgrade mozilla-thunderbird-locale-pl | Nov 8, 2024 | Jul 27, 2006 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub