Mozilla Firefox before 1.5.0.7, Thunderbird before 1.5.0.7, and SeaMonkey before 1.0.5 allows remote attackers to cause a denial of service (crash) via a malformed JavaScript regular expression that ends with a backslash in an unterminated character set ("[\\"), which leads to a buffer over-read.
CVSS Details
- CVSS 3.1 Base Score: 4.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade thunderbird | Jul 30, 2024 | Sep 15, 2006 |
| Freebsd | — | Upgrade linux-thunderbirdUpgrade linux-mozilla-develUpgrade linux-firefoxUpgrade firefoxUpgrade mozilla-thunderbirdUpgrade linux-seamonkeyUpgrade thunderbirdUpgrade mozillaUpgrade linux-firefox-develUpgrade linux-seamonkey-develUpgrade linux-mozillaUpgrade seamonkey | Dec 10, 2025 | Sep 15, 2006 |
| Gentoo Linux | — | Upgrade www-client/seamonkey.Upgrade mail-client/mozilla-thunderbird.Upgrade mail-client/mozilla-thunderbird-bin.Upgrade www-client/mozilla-firefox.Upgrade www-client/mozilla-firefox-bin. | Oct 30, 2017 | Sep 15, 2006 |
| Ubuntu | — | Upgrade mozilla-thunderbird-locale-nlUpgrade mozilla-thunderbirdUpgrade mozilla-thunderbird-locale-frUpgrade mozilla-thunderbird-enigmailUpgrade mozilla-thunderbird-locale-caUpgrade mozilla-thunderbird-locale-ukUpgrade libnss3Upgrade mozilla-thunderbird-locale-deUpgrade mozilla-thunderbird-inspectorUpgrade firefoxUpgrade mozilla-thunderbird-typeaheadfindUpgrade mozilla-thunderbird-locale-itUpgrade mozilla-thunderbird-locale-pl | Nov 8, 2024 | Sep 15, 2006 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub