Heap-based buffer overflow in Mozilla Thunderbird before 1.5.0.5 and SeaMonkey before 1.0.3 allows remote attackers to cause a denial of service (crash) via a VCard attachment with a malformed base64 field, which copies more data than expected due to an integer underflow.
CVSS Details
- CVSS 3.1 Base Score: 5.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade thunderbird | Jul 30, 2024 | Jul 27, 2006 |
| Freebsd | — | Upgrade firefoxUpgrade linux-seamonkeyUpgrade linux-firefox-develUpgrade linux-mozilla-develUpgrade linux-thunderbirdUpgrade mozillaUpgrade thunderbirdUpgrade linux-mozillaUpgrade mozilla-thunderbirdUpgrade linux-firefoxUpgrade seamonkey | Dec 10, 2025 | Jul 27, 2006 |
| Gentoo Linux | — | Upgrade mail-client/mozilla-thunderbird.Upgrade mail-client/mozilla-thunderbird-bin.Upgrade www-client/seamonkey. | Oct 30, 2017 | Jul 27, 2006 |
| Mozilla Seamonkey | — | Upgrade to Mozilla SeaMonkey version 1.0.3 | Nov 21, 2013 | Jul 27, 2006 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 1.5.0.5 | Nov 21, 2013 | Jul 27, 2006 |
| Ubuntu | — | Upgrade mozilla-thunderbird-inspectorUpgrade mozilla-thunderbird-locale-ukUpgrade mozilla-thunderbird-locale-deUpgrade mozilla-thunderbird-typeaheadfindUpgrade mozilla-thunderbird-locale-plUpgrade mozilla-thunderbird-locale-nlUpgrade mozilla-thunderbirdUpgrade mozilla-thunderbird-locale-caUpgrade mozilla-thunderbird-locale-frUpgrade mozilla-thunderbird-enigmailUpgrade mozilla-thunderbird-locale-it | Nov 8, 2024 | Jul 27, 2006 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub