The nsAuthSSPI::Unwrap function in extensions/auth/nsAuthSSPI.cpp in Mozilla Thunderbird before 2.0.0.24 and SeaMonkey before 1.1.19 on Windows Vista, Windows Server 2008 R2, and Windows 7 allows remote SMTP, IMAP, and POP servers to cause a denial of service (heap memory corruption and application crash) or possibly execute arbitrary code via crafted data in a session that uses SSPI.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade seamonkeyUpgrade linux-seamonkeyUpgrade linux-thunderbirdUpgrade thunderbird | Dec 10, 2025 | Mar 19, 2010 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 2.0.0.24 | Feb 22, 2012 | Mar 22, 2010 |
| Suse | — | Upgrade mozilla-mailUpgrade seamonkey-ircUpgrade seamonkey-mailUpgrade seamonkey-venkmanUpgrade MozillaThunderbirdUpgrade seamonkey-spellcheckerUpgrade MozillaThunderbird-develUpgrade mozillaUpgrade mozilla-dom-inspectorUpgrade mozilla-venkmanUpgrade mozilla-ircUpgrade seamonkey-dom-inspectorUpgrade seamonkeyUpgrade mozilla-develUpgrade MozillaThunderbird-translations | Feb 17, 2015 | Mar 22, 2010 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub