Heap-based buffer overflow in the _cairo_pen_init function in Mozilla Firefox 2.x before 2.0.0.2, Thunderbird before 1.5.0.10, and SeaMonkey before 1.0.8 allows remote attackers to execute arbitrary code via a large stroke-width attribute in the clipPath element in an SVG file.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade mozilla-thunderbirdUpgrade linux-thunderbirdUpgrade firefox-jaUpgrade firefoxUpgrade linux-firefoxUpgrade linux-firefox-develUpgrade linux-seamonkeyUpgrade seamonkeyUpgrade lightningUpgrade linux-mozillaUpgrade mozillaUpgrade thunderbirdUpgrade linux-seamonkey-develUpgrade linux-mozilla-devel | Dec 10, 2025 | Feb 24, 2007 |
| Gentoo Linux | — | Upgrade www-client/mozilla-firefox.Upgrade mail-client/mozilla-thunderbird-bin.Upgrade mail-client/mozilla-thunderbird.Upgrade www-client/mozilla-firefox-bin.Upgrade www-client/seamonkey-bin.Upgrade www-client/seamonkey. | Oct 30, 2017 | Feb 26, 2007 |
| Mfsa2007 01 | — | Upgrade to Mozilla Firefox version 1.5.0.10Upgrade to Mozilla Firefox version 2.0.0.2 | Jun 14, 2012 | Feb 26, 2007 |
| Mozilla Seamonkey | — | Upgrade to Mozilla SeaMonkey version 1.0.8 | Feb 3, 2012 | Feb 26, 2007 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 1.5.0.10 | Feb 22, 2012 | Feb 26, 2007 |
| Suse | — | Upgrade MozillaFirefox-develUpgrade MozillaFirefox-translations-commonUpgrade MozillaFirefox-translations-otherUpgrade MozillaFirefoxUpgrade MozillaFirefox-translations | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade libnspr4Upgrade mozilla-thunderbirdUpgrade firefoxUpgrade libnss3 | Nov 8, 2024 | Feb 26, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub