Use-after-free vulnerability in the LiveConnect bridge code for Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to cause a denial of service (crash) via unknown vectors.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade firefox-esr | Jul 30, 2024 | Dec 20, 2006 |
| Gentoo Linux | — | Upgrade www-client/mozilla-firefox.Upgrade www-client/seamonkey.Upgrade mail-client/mozilla-thunderbird.Upgrade www-client/mozilla-firefox-bin.Upgrade mail-client/mozilla-thunderbird-bin. | Oct 30, 2017 | Dec 19, 2006 |
| Mfsa2006 71 | — | Upgrade to Mozilla Firefox version 1.5.0.9Upgrade to Mozilla Firefox version 2.0.0.1 | Jun 14, 2012 | Dec 19, 2006 |
| Mozilla Seamonkey | — | Upgrade to Mozilla SeaMonkey version 1.0.7 | Feb 3, 2012 | Dec 19, 2006 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 1.5.0.9 | Feb 22, 2012 | Dec 19, 2006 |
| Suse | — | Upgrade suse-releaseUpgrade MozillaFirefoxUpgrade MozillaFirefox-translationsUpgrade MozillaThunderbirdUpgrade MozillaThunderbird-translations | Feb 17, 2015 | Dec 19, 2006 |
| Ubuntu | — | Upgrade firefox-devUpgrade mozilla-thunderbird-devUpgrade libnspr4Upgrade mozilla-thunderbirdUpgrade libnspr-devUpgrade firefoxUpgrade libnss-devUpgrade libnss3 | Nov 8, 2024 | Dec 20, 2006 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub