Mozilla Firefox before 3.5.9 and 3.6.x before 3.6.2, and SeaMonkey before 2.0.4, executes a mail application in situations where an IMG element has a SRC attribute that is a redirect to a mailto: URL, which allows remote attackers to cause a denial of service (excessive application launches) via an HTML document with many images.
CVSS Details
- CVSS 3.1 Base Score: 7.1
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade linux-firefoxUpgrade linux-f10-nssUpgrade seamonkeyUpgrade linux-firefox-develUpgrade thunderbirdUpgrade firefoxUpgrade nss | Dec 10, 2025 | Mar 30, 2010 |
| Gentoo Linux | — | Upgrade www-client/firefox-bin.Upgrade mail-client/thunderbird.Upgrade www-client/seamonkey.Upgrade net-libs/xulrunner-bin.Upgrade mail-client/mozilla-thunderbird-bin.Upgrade mail-client/mozilla-thunderbird.Upgrade mail-client/thunderbird-bin.Upgrade www-client/mozilla-firefox.Upgrade www-client/firefox.Upgrade www-client/seamonkey-bin.Upgrade dev-libs/nss.Upgrade www-client/icecat.Upgrade www-client/mozilla-firefox-bin.Upgrade net-libs/xulrunner. | Oct 30, 2017 | Apr 5, 2010 |
| Mfsa2010 23 | — | Upgrade to Mozilla Firefox version 3.5.9Upgrade to Mozilla Firefox version 3.6.2 | Jun 14, 2012 | Apr 5, 2010 |
| Mozilla Seamonkey | — | Upgrade to Mozilla SeaMonkey version 2.0.4 | Feb 3, 2012 | Apr 5, 2010 |
| Suse | — | Upgrade mozilla-nspr-32bitUpgrade mozilla-xulrunner192Upgrade mozilla-xulrunner191-gnomevfsUpgrade MozillaFirefox-translations-commonUpgrade mozilla-nsprUpgrade mozilla-nss-toolsUpgrade mozilla-xulrunner192-develUpgrade mozilla-xulrunner190-32bitUpgrade mozilla-xulrunner190Upgrade mozilla-xulrunner190-translationsUpgrade orbit2Upgrade MozillaFirefox-translationsUpgrade mozilla-xulrunner191-32bitUpgrade mozilla-xulrunner192-gnome-32bitUpgrade mozilla-xulrunner192-gnomeUpgrade mozilla-xulrunner192-32bitUpgrade libidl-32bitUpgrade mozilla-xulrunner192-translationsUpgrade MozillaFirefoxUpgrade MozillaFirefox-develUpgrade mozilla-xulrunner191-x86Upgrade mozilla-nss-32bitUpgrade libfreebl3-x86Upgrade MozillaFirefox-translations-otherUpgrade libidl-x86Upgrade mozilla-nss-x86Upgrade gconf2-x86Upgrade mozilla-xulrunner190-gnomevfsUpgrade orbit2-32bitUpgrade libfreebl3Upgrade mozilla-xulrunner190-x86Upgrade libidlUpgrade gconf2-32bitUpgrade mozilla-nssUpgrade mozilla-xulrunner191Upgrade mozilla-xulrunner192-translations-32bitUpgrade orbit2-x86Upgrade mozilla-xulrunner191-translationsUpgrade mozilla-nspr-x86Upgrade libfreebl3-32bitUpgrade MozillaFirefox-branding-SLEDUpgrade mozilla-xulrunner192-x86Upgrade gconf2 | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade firefox-3.5Upgrade xulrunner-1.9.1 | Nov 8, 2024 | Apr 5, 2010 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub