Mozilla Thunderbird before 2.0.0.22 and SeaMonkey before 1.1.17 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a multipart/alternative e-mail message containing a text/enhanced part that triggers access to an incorrect object type.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade seamonkey-js-debuggerUpgrade seamonkey-nspr-develUpgrade seamonkey-nssUpgrade seamonkey-develUpgrade seamonkey-dom-inspectorUpgrade seamonkey-nss-develUpgrade seamonkeyUpgrade thunderbirdUpgrade seamonkey-mailUpgrade seamonkey-chatUpgrade seamonkey-nspr | Dec 1, 2016 | Jun 25, 2009 |
| Gentoo Linux | — | Upgrade www-client/firefox.Upgrade www-client/seamonkey.Upgrade net-libs/xulrunner.Upgrade mail-client/mozilla-thunderbird.Upgrade dev-libs/nss.Upgrade www-client/icecat.Upgrade www-client/mozilla-firefox.Upgrade www-client/firefox-bin.Upgrade www-client/seamonkey-bin.Upgrade mail-client/thunderbird.Upgrade www-client/mozilla-firefox-bin.Upgrade mail-client/thunderbird-bin.Upgrade mail-client/mozilla-thunderbird-bin.Upgrade net-libs/xulrunner-bin. | Oct 30, 2017 | Jun 25, 2009 |
| Suse | — | Upgrade seamonkey-mailUpgrade seamonkeyUpgrade seamonkey-dom-inspectorUpgrade seamonkey-spellcheckerUpgrade mozilla-develUpgrade mozilla-dom-inspectorUpgrade mozilla-venkmanUpgrade seamonkey-venkmanUpgrade mozilla-ircUpgrade mozillaUpgrade seamonkey-ircUpgrade mozilla-mail | Dec 12, 2013 | Jun 25, 2009 |
| Ubuntu | — | Upgrade thunderbirdUpgrade seamonkey | Nov 19, 2024 | Jun 25, 2009 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub