Multiple vulnerabilities in Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via Javascript that leads to memory corruption, including (1) nsListControlFrame::FireMenuItemActiveEvent, (2) buffer overflows in the string class in out-of-memory conditions, (3) table row and column groups, (4) "anonymous box selectors outside of UA stylesheets," (5) stale references to "removed nodes," and (6) running the crypto.generateCRMFRequest callback on deleted context.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade thunderbird | Jul 30, 2024 | Jul 27, 2006 |
| Freebsd | — | Upgrade linux-firefoxUpgrade linux-mozillaUpgrade mozillaUpgrade linux-firefox-develUpgrade linux-mozilla-develUpgrade seamonkeyUpgrade firefoxUpgrade thunderbirdUpgrade linux-thunderbirdUpgrade linux-seamonkeyUpgrade mozilla-thunderbird | Dec 10, 2025 | Jul 27, 2006 |
| Gentoo Linux | — | Upgrade www-client/seamonkey.Upgrade www-client/mozilla-firefox.Upgrade www-client/mozilla-firefox-bin.Upgrade mail-client/mozilla-thunderbird.Upgrade mail-client/mozilla-thunderbird-bin. | Oct 30, 2017 | Jul 27, 2006 |
| Mfsa2006 55 | — | Upgrade to Mozilla Firefox version 1.5.0.5Upgrade to the latest version of Mozilla Firefox | Aug 1, 2006 | Jul 26, 2006 |
| Ubuntu | — | Upgrade mozilla-thunderbird-locale-itUpgrade mozilla-thunderbirdUpgrade libnss3Upgrade mozilla-thunderbird-inspectorUpgrade mozilla-thunderbird-locale-nlUpgrade mozilla-mailnewsUpgrade mozilla-thunderbird-locale-plUpgrade firefoxUpgrade mozilla-browserUpgrade mozilla-thunderbird-locale-deUpgrade mozilla-psmUpgrade mozilla-thunderbird-typeaheadfindUpgrade mozilla-thunderbird-locale-caUpgrade mozilla-thunderbird-locale-ukUpgrade mozilla-thunderbird-enigmailUpgrade libnspr4Upgrade mozilla-thunderbird-locale-fr | Nov 8, 2024 | Jul 27, 2006 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub