Multiple vulnerabilities in the Javascript engine in Mozilla Firefox before 2.0.0.8, Thunderbird before 2.0.0.8, and SeaMonkey before 1.1.5 allow remote attackers to cause a denial of service (crash) via crafted HTML that triggers memory corruption.
CVSS Details
- CVSS 3.1 Base Score: 6.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade www-client/mozilla-firefox.Upgrade www-client/seamonkey.Upgrade mail-client/mozilla-thunderbird.Upgrade www-client/seamonkey-bin.Upgrade mail-client/mozilla-thunderbird-bin.Upgrade net-libs/xulrunner.Upgrade www-client/mozilla-firefox-bin. | Oct 30, 2017 | Oct 21, 2007 |
| Mfsa2007 29 | — | Upgrade to Mozilla Firefox version 2.0.0.8 | Jun 14, 2012 | Oct 21, 2007 |
| Mozilla Seamonkey | — | Upgrade to Mozilla SeaMonkey version 1.1.5 | Feb 3, 2012 | Oct 21, 2007 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 1.5.0.14Upgrade to Mozilla Thunderbird version 2.0.0.9 | Feb 22, 2012 | Oct 21, 2007 |
| Oracle_linux | — | Upgrade firefoxUpgrade firefox-devel | Oct 16, 2024 | Oct 21, 2007 |
| Suse | — | Upgrade mozilla-ircUpgrade MozillaFirefoxUpgrade MozillaFirefox-translationsUpgrade mozilla-dom-inspectorUpgrade mozilla-huUpgrade mozilla-venkmanUpgrade mozilla-develUpgrade seamonkey-venkmanUpgrade MozillaThunderbird-translationsUpgrade seamonkeyUpgrade seamonkey-dom-inspectorUpgrade mozilla-mailUpgrade seamonkey-mailUpgrade seamonkey-ircUpgrade mozilla-calendarUpgrade mozillaUpgrade suse-releaseUpgrade MozillaThunderbirdUpgrade mozilla-csUpgrade seamonkey-spellcheckerUpgrade mozilla-deat | Feb 17, 2015 | Oct 21, 2007 |
| Ubuntu | — | Upgrade firefoxUpgrade mozilla-thunderbird | Nov 8, 2024 | Oct 21, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub