The block reflow implementation in Mozilla Firefox before 2.0.0.15, Thunderbird 2.0.0.14 and earlier, and SeaMonkey before 1.1.10 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an image whose display requires more pixels than nscoord_MAX, related to nsBlockFrame::DrainOverflowLines.
CVSS Details
- CVSS 3.1 Base Score: 8.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade devhelp-develUpgrade xulrunner-devel-unstableUpgrade xulrunner-develUpgrade yelpUpgrade devhelpUpgrade firefoxUpgrade xulrunner | Dec 1, 2016 | Jul 7, 2008 |
| Gentoo Linux | — | Upgrade mail-client/mozilla-thunderbird.Upgrade mail-client/mozilla-thunderbird-bin.Upgrade www-client/mozilla-firefox-bin.Upgrade www-client/seamonkey-bin.Upgrade net-libs/xulrunner-bin.Upgrade net-libs/xulrunner.Upgrade www-client/seamonkey.Upgrade www-client/mozilla-firefox. | Oct 30, 2017 | Jul 7, 2008 |
| Mfsa2008 33 | — | Upgrade to Mozilla Firefox version 2.0.0.15 | Jun 14, 2012 | Jul 7, 2008 |
| Mozilla Seamonkey | — | Upgrade to Mozilla SeaMonkey version 1.1.10 | Feb 3, 2012 | Jul 7, 2008 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 2.0.0.16 | Feb 22, 2012 | Jul 7, 2008 |
| Oracle_linux | — | Upgrade yelpUpgrade devhelpUpgrade firefoxUpgrade devhelp-develUpgrade xulrunnerUpgrade xulrunner-develUpgrade xulrunner-devel-unstable | Oct 16, 2024 | Jul 7, 2008 |
| Suse | — | Upgrade seamonkey-dom-inspectorUpgrade seamonkey-mailUpgrade seamonkey-spellcheckerUpgrade seamonkeyUpgrade seamonkey-venkmanUpgrade MozillaFirefoxUpgrade MozillaFirefox-translationsUpgrade seamonkey-ircUpgrade suse-release | Feb 17, 2015 | Jul 7, 2008 |
| Ubuntu | — | Upgrade mozilla-thunderbirdUpgrade firefoxUpgrade thunderbird | Nov 8, 2024 | Jul 7, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub