Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the JavaScript engine and (1) misinterpretation of the characteristics of Namespace and QName in jsxml.c, (2) misuse of signed integers in the nsEscapeCount function in nsEscape.cpp, and (3) interaction of JavaScript garbage collection with certain use of an NPObject in the nsNPObjWrapper::GetNewOrUsed function in nsJSNPRuntime.cpp.
CVSS Details
- CVSS 3.1 Base Score: 9.6
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade seamonkey-mailUpgrade seamonkeyUpgrade devhelp-develUpgrade thunderbirdUpgrade seamonkey-dom-inspectorUpgrade seamonkey-js-debuggerUpgrade firefoxUpgrade seamonkey-chatUpgrade devhelpUpgrade seamonkey-devel | Dec 1, 2016 | Sep 24, 2008 |
| Freebsd | — | Upgrade linux-seamonkey-develUpgrade linux-flockUpgrade linux-firefox-develUpgrade linux-thunderbirdUpgrade firefoxUpgrade seamonkeyUpgrade linux-seamonkeyUpgrade linux-firefoxUpgrade flockUpgrade thunderbird | Dec 10, 2025 | Sep 24, 2008 |
| Gentoo Linux | — | Upgrade net-libs/xulrunner-bin.Upgrade www-client/seamonkey-bin.Upgrade mail-client/thunderbird.Upgrade www-client/seamonkey.Upgrade www-client/firefox-bin.Upgrade www-client/firefox.Upgrade www-client/icecat.Upgrade mail-client/thunderbird-bin.Upgrade dev-libs/nss.Upgrade net-libs/xulrunner.Upgrade mail-client/mozilla-thunderbird.Upgrade mail-client/mozilla-thunderbird-bin.Upgrade www-client/mozilla-firefox.Upgrade www-client/mozilla-firefox-bin. | Oct 30, 2017 | Sep 24, 2008 |
| Mfsa2008 42 | — | Upgrade to Mozilla Firefox version 3.0.2Upgrade to Mozilla Firefox version 2.0.0.17 | Jun 14, 2012 | Sep 24, 2008 |
| Mozilla Seamonkey | — | Upgrade to Mozilla SeaMonkey version 1.1.12 | Feb 3, 2012 | Sep 24, 2008 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 2.0.0.17 | Feb 22, 2012 | Sep 24, 2008 |
| Oracle_linux | — | Upgrade nss-toolsUpgrade nssUpgrade xulrunnerUpgrade xulrunner-develUpgrade nss-pkcs11-develUpgrade nss-develUpgrade xulrunner-devel-unstableUpgrade devhelpUpgrade yelpUpgrade devhelp-develUpgrade firefox | Oct 16, 2024 | Sep 24, 2008 |
| Suse | — | Upgrade mozilla-xulrunner181-32bitUpgrade mozilla-xulrunner190-translations-64bitUpgrade mozillaUpgrade mozilla-calendarUpgrade mozilla-huUpgrade MozillaThunderbirdUpgrade seamonkey-dom-inspectorUpgrade mozilla-xulrunner181-l10nUpgrade mozilla-dom-inspectorUpgrade seamonkey-venkmanUpgrade mozilla-xulrunner190-32bitUpgrade MozillaThunderbird-develUpgrade mozilla-xulrunner181Upgrade mozilla-deatUpgrade mozilla-xulrunner181-64bitUpgrade mozilla-xulrunner190-translations-32bitUpgrade mozilla-xulrunner190-64bitUpgrade seamonkey-mailUpgrade gecko-sdkUpgrade suse-releaseUpgrade mozilla-xulrunner190-gnomevfs-64bitUpgrade mozilla-xulrunner181-develUpgrade mozilla-ircUpgrade mozilla-xulrunner190-gnomevfsUpgrade mozilla-xulrunner190-translationsUpgrade MozillaFirefox-translationsUpgrade seamonkey-ircUpgrade mozilla-xulrunner190-gnomevfs-32bitUpgrade MozillaThunderbird-translationsUpgrade seamonkeyUpgrade mozilla-venkmanUpgrade mozilla-csUpgrade MozillaFirefoxUpgrade seamonkey-spellcheckerUpgrade mozilla-develUpgrade mozilla-mailUpgrade mozilla-xulrunner190-develUpgrade mozilla-xulrunner190 | Feb 17, 2015 | Sep 24, 2008 |
| Ubuntu | — | Upgrade firefox-3.0Upgrade xulrunner-1.9Upgrade thunderbirdUpgrade firefoxUpgrade mozilla-thunderbird | Nov 8, 2024 | Sep 24, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub