The layout engine in Mozilla Firefox 3.x before 3.0.5, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to cause a denial of service (crash) via vectors that trigger memory corruption, related to the GetXMLEntity and FastAppendChar functions.
CVSS Details
- CVSS 3.1 Base Score: 4.7
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade xulrunner-devel-unstableUpgrade seamonkey-develUpgrade seamonkey-nss-develUpgrade xulrunner-develUpgrade nss-pkcs11-develUpgrade seamonkey-mailUpgrade seamonkeyUpgrade seamonkey-js-debuggerUpgrade seamonkey-nssUpgrade seamonkey-chatUpgrade nssUpgrade nss-toolsUpgrade seamonkey-dom-inspectorUpgrade seamonkey-nsprUpgrade nss-develUpgrade nsprUpgrade thunderbirdUpgrade firefoxUpgrade xulrunnerUpgrade nspr-develUpgrade seamonkey-nspr-devel | Dec 1, 2016 | Dec 17, 2008 |
| Freebsd | — | Upgrade linux-thunderbirdUpgrade thunderbirdUpgrade linux-seamonkeyUpgrade firefoxUpgrade linux-firefoxUpgrade seamonkey | Dec 10, 2025 | Dec 19, 2008 |
| Gentoo Linux | — | Upgrade mail-client/mozilla-thunderbird-bin.Upgrade mail-client/thunderbird.Upgrade www-client/seamonkey-bin.Upgrade net-libs/xulrunner-bin.Upgrade net-libs/xulrunner.Upgrade mail-client/thunderbird-bin.Upgrade www-client/mozilla-firefox.Upgrade www-client/firefox-bin.Upgrade www-client/icecat.Upgrade www-client/firefox.Upgrade mail-client/mozilla-thunderbird.Upgrade www-client/mozilla-firefox-bin.Upgrade www-client/seamonkey.Upgrade dev-libs/nss. | Oct 30, 2017 | Dec 17, 2008 |
| Mfsa2008 60 | — | Upgrade to Mozilla Firefox version 2.0.0.19Upgrade to Mozilla Firefox version 3.0.5 | Jun 14, 2012 | Dec 17, 2008 |
| Mozilla Seamonkey | — | Upgrade to Mozilla SeaMonkey version 1.1.14 | Feb 3, 2012 | Dec 17, 2008 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 2.0.0.19 | Feb 22, 2012 | Dec 17, 2008 |
| Oracle_linux | — | Upgrade nss-pkcs11-develUpgrade xulrunner-develUpgrade xulrunner-devel-unstableUpgrade nss-develUpgrade nssUpgrade nspr-develUpgrade firefoxUpgrade xulrunnerUpgrade nsprUpgrade nss-tools | Oct 16, 2024 | Dec 17, 2008 |
| Suse | — | Upgrade MozillaFirefoxUpgrade MozillaFirefox-translations | Feb 17, 2015 | Dec 17, 2008 |
| Ubuntu | — | Upgrade abrowserUpgrade firefox-3.0Upgrade xulrunner-1.9 | Nov 8, 2024 | Dec 17, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub