The JavaScript engine in Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to (1) js_LeaveSharpObject, (2) ParseXMLSource, and (3) a certain assertion in jsinterp.c; and other vectors.
CVSS Details
- CVSS 3.1 Base Score: 8.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade seamonkeyUpgrade seamonkey-nssUpgrade seamonkey-nspr-develUpgrade firefoxUpgrade seamonkey-chatUpgrade thunderbirdUpgrade seamonkey-dom-inspectorUpgrade seamonkey-js-debuggerUpgrade seamonkey-nsprUpgrade seamonkey-develUpgrade xulrunner-develUpgrade xulrunner-devel-unstableUpgrade seamonkey-nss-develUpgrade xulrunnerUpgrade seamonkey-mail | Dec 1, 2016 | Jun 12, 2009 |
| Freebsd | — | Upgrade linux-firefoxUpgrade linux-thunderbirdUpgrade firefoxUpgrade linux-seamonkeyUpgrade seamonkeyUpgrade linux-firefox-develUpgrade thunderbird | Dec 10, 2025 | Jun 12, 2009 |
| Gentoo Linux | — | Upgrade www-client/firefox-bin.Upgrade www-client/icecat.Upgrade dev-libs/nss.Upgrade mail-client/thunderbird-bin.Upgrade mail-client/mozilla-thunderbird.Upgrade www-client/mozilla-firefox-bin.Upgrade net-libs/xulrunner.Upgrade www-client/firefox.Upgrade www-client/mozilla-firefox.Upgrade mail-client/mozilla-thunderbird-bin.Upgrade www-client/seamonkey-bin.Upgrade mail-client/thunderbird.Upgrade www-client/seamonkey.Upgrade net-libs/xulrunner-bin. | Oct 30, 2017 | Jun 12, 2009 |
| Mfsa2009 24 | — | Upgrade to Mozilla Firefox version 3.0.11 | Jun 14, 2012 | Jun 12, 2009 |
| Mozilla Seamonkey | — | Upgrade to Mozilla SeaMonkey version 1.1.17 | Feb 3, 2012 | Jun 12, 2009 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 2.0.0.22 | Feb 22, 2012 | Jun 12, 2009 |
| Oracle_linux | — | Upgrade firefoxUpgrade xulrunner-devel-unstableUpgrade xulrunner-develUpgrade xulrunner | Oct 16, 2024 | Jun 12, 2009 |
| Suse | — | Upgrade mozilla-xulrunner191-32bitUpgrade mozilla-xulrunner192-translationsUpgrade mozilla-xulrunner192-gnomeUpgrade mozilla-nsprUpgrade mozilla-nspr-32bitUpgrade mozilla-nss-toolsUpgrade mozilla-xulrunner190-32bitUpgrade mozilla-xulrunner190Upgrade orbit2Upgrade MozillaFirefoxUpgrade mozilla-xulrunner191Upgrade mozilla-xulrunner192-32bitUpgrade MozillaFirefox-translationsUpgrade mozilla-xulrunner191-gnomevfsUpgrade mozilla-xulrunner191-x86Upgrade mozilla-nspr-x86Upgrade libidlUpgrade libidl-32bitUpgrade gconf2-32bitUpgrade libfreebl3Upgrade libidl-x86Upgrade mozilla-xulrunner191-translationsUpgrade mozilla-nss-x86Upgrade mozilla-xulrunner190-x86Upgrade libfreebl3-32bitUpgrade mozilla-xulrunner190-gnomevfsUpgrade gconf2Upgrade mozilla-nss-32bitUpgrade mozilla-xulrunner190-translationsUpgrade gconf2-x86Upgrade orbit2-32bitUpgrade MozillaFirefox-branding-SLEDUpgrade libfreebl3-x86Upgrade mozilla-nssUpgrade mozilla-xulrunner192-x86Upgrade orbit2-x86Upgrade mozilla-xulrunner192 | Feb 17, 2015 | Jul 9, 2013 |
| Ubuntu | — | Upgrade xulrunner-1.9Upgrade firefox-3.0Upgrade thunderbirdUpgrade abrowser | Nov 8, 2024 | Jun 12, 2009 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub