The browser engine in Mozilla Firefox 3.x before 3.0.9, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.16 allows remote attackers to cause a denial of service (application crash) and possibly trigger memory corruption via vectors related to (1) nsAsyncInstantiateEvent::Run, (2) nsStyleContext::Destroy, (3) nsComputedDOMStyle::GetWidth, (4) the xslt_attributeset_ImportSameName.html test case for the XSLT stylesheet compiler, (5) nsXULDocument::SynchronizeBroadcastListener, (6) IsBindingAncestor, (7) PL_DHashTableOperate and nsEditor::EndUpdateViewBatch, and (8) gfxSkipCharsIterator::SetOffsets, and other vectors.
CVSS Details
- CVSS 3.1 Base Score: 4.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade firefoxUpgrade xulrunner-develUpgrade xulrunner-devel-unstableUpgrade xulrunner | Dec 1, 2016 | Apr 22, 2009 |
| Freebsd | — | Upgrade linux-firefoxUpgrade linux-seamonkey-develUpgrade firefoxUpgrade thunderbirdUpgrade linux-seamonkeyUpgrade seamonkeyUpgrade linux-thunderbirdUpgrade linux-firefox-devel | Dec 10, 2025 | Apr 22, 2009 |
| Gentoo Linux | — | Upgrade www-client/seamonkey.Upgrade www-client/firefox.Upgrade mail-client/mozilla-thunderbird.Upgrade net-libs/xulrunner-bin.Upgrade mail-client/thunderbird-bin.Upgrade mail-client/thunderbird.Upgrade www-client/seamonkey-bin.Upgrade www-client/icecat.Upgrade net-libs/xulrunner.Upgrade dev-libs/nss.Upgrade www-client/mozilla-firefox.Upgrade mail-client/mozilla-thunderbird-bin.Upgrade www-client/mozilla-firefox-bin.Upgrade www-client/firefox-bin. | Oct 30, 2017 | Apr 22, 2009 |
| Mfsa2009 14 | — | Upgrade to Mozilla Firefox version 3.0.9 | Jun 14, 2012 | Apr 22, 2009 |
| Mozilla Seamonkey | — | Upgrade to Mozilla SeaMonkey version 1.1.16 | Feb 3, 2012 | Apr 22, 2009 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 2.0.0.22 | Feb 22, 2012 | Apr 22, 2009 |
| Oracle_linux | — | Upgrade firefoxUpgrade xulrunner-devel-unstableUpgrade xulrunnerUpgrade xulrunner-devel | Oct 16, 2024 | Apr 22, 2009 |
| Suse | — | Upgrade gconf2Upgrade libidl-x86Upgrade mozilla-nss-x86Upgrade mozilla-xulrunner191-gnomevfsUpgrade mozilla-nspr-32bitUpgrade mozilla-xulrunner190-gnomevfsUpgrade mozilla-xulrunner192-gnomeUpgrade mozilla-nss-32bitUpgrade mozilla-xulrunner191-translationsUpgrade orbit2Upgrade mozilla-xulrunner192-translationsUpgrade libidlUpgrade mozilla-nss-toolsUpgrade orbit2-32bitUpgrade mozilla-xulrunner192-32bitUpgrade mozilla-xulrunner191-32bitUpgrade mozilla-xulrunner190-translationsUpgrade mozilla-xulrunner191Upgrade MozillaFirefox-translations-otherUpgrade MozillaFirefoxUpgrade mozilla-xulrunner190-x86Upgrade mozilla-nssUpgrade MozillaFirefox-branding-SLEDUpgrade libfreebl3-x86Upgrade mozilla-xulrunner190-32bitUpgrade libfreebl3Upgrade gconf2-x86Upgrade MozillaFirefox-translations-commonUpgrade mozilla-xulrunner190Upgrade MozillaFirefox-translationsUpgrade mozilla-nspr-x86Upgrade mozilla-nsprUpgrade orbit2-x86Upgrade mozilla-xulrunner192Upgrade mozilla-xulrunner192-x86Upgrade libfreebl3-32bitUpgrade gconf2-32bitUpgrade mozilla-xulrunner191-x86Upgrade MozillaFirefox-develUpgrade libidl-32bit | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade firefox-3.0Upgrade abrowserUpgrade xulrunner-1.9 | Nov 8, 2024 | Apr 22, 2009 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub