Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to execute arbitrary code by appending an SVG comment DOM node to another type of document, which triggers memory corruption.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade firefox-esr | Jul 30, 2024 | Dec 20, 2006 |
| Gentoo Linux | — | Upgrade www-client/seamonkey.Upgrade www-client/mozilla-firefox.Upgrade www-client/mozilla-firefox-bin. | Oct 30, 2017 | Dec 19, 2006 |
| Mfsa2006 73 | — | Upgrade to Mozilla Firefox version 1.5.0.9Upgrade to Mozilla Firefox version 2.0.0.1 | Jun 14, 2012 | Dec 19, 2006 |
| Mozilla Seamonkey | — | Upgrade to Mozilla SeaMonkey version 1.0.7 | Feb 3, 2012 | Dec 19, 2006 |
| Suse | — | Upgrade MozillaFirefox-translationsUpgrade MozillaFirefoxUpgrade MozillaThunderbirdUpgrade MozillaThunderbird-translationsUpgrade suse-release | Feb 17, 2015 | Dec 19, 2006 |
| Ubuntu | — | Upgrade libnspr-devUpgrade libnss3Upgrade libnss-devUpgrade firefoxUpgrade libnspr4Upgrade firefox-dev | Nov 8, 2024 | Dec 20, 2006 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub