Untrusted search path vulnerability in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 on Windows XP allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll that is located in the same folder as a .htm, .html, .jtx, .mfp, or .eml file.
CVSS Details
- CVSS 3.1 Base Score: 9.6
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade libxulUpgrade seamonkeyUpgrade linux-firefox-develUpgrade firefoxUpgrade thunderbirdUpgrade linux-firefox | Dec 10, 2025 | Sep 8, 2010 |
| Gentoo Linux | — | Upgrade www-client/firefox-bin.Upgrade www-client/seamonkey-bin.Upgrade mail-client/thunderbird.Upgrade www-client/seamonkey.Upgrade net-libs/xulrunner-bin.Upgrade net-libs/xulrunner.Upgrade www-client/firefox.Upgrade www-client/icecat.Upgrade www-client/mozilla-firefox.Upgrade mail-client/mozilla-thunderbird.Upgrade dev-libs/nss.Upgrade mail-client/thunderbird-bin.Upgrade www-client/mozilla-firefox-bin.Upgrade mail-client/mozilla-thunderbird-bin. | Oct 30, 2017 | Aug 26, 2010 |
| Mfsa2010 52 | — | Upgrade to Mozilla Firefox version 3.6.9Upgrade to Mozilla Firefox version 3.5.12 | Jun 14, 2012 | Aug 26, 2010 |
| Mozilla Seamonkey | — | Upgrade to Mozilla SeaMonkey version 2.0.7 | Feb 3, 2012 | Aug 26, 2010 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 3.0.7Upgrade to Mozilla Thunderbird version 3.1.3 | Feb 22, 2012 | Aug 26, 2010 |
| Suse | — | Upgrade mozillathunderbird-translations-otherUpgrade mozillathunderbirdUpgrade mozilla-xulrunner192-buildsymbolsUpgrade mozilla-xulrunner192-translations-otherUpgrade mozillafirefox-translations-commonUpgrade mozilla-xulrunner191Upgrade sap-aio-releaseUpgrade MozillaFirefox-translationsUpgrade seamonkey-translations-otherUpgrade mozilla-xulrunner192-develUpgrade seamonkeyUpgrade seamonkey-dom-inspectorUpgrade seamonkey-ircUpgrade seamonkey-translations-commonUpgrade mozilla-xulrunner191-gnomevfsUpgrade mozillafirefox-translations-otherUpgrade mozilla-xulrunner192-translations-commonUpgrade mozillafirefox-branding-upstreamUpgrade mozilla-xulrunner192-gnomeUpgrade mozilla-xulrunner191-develUpgrade enigmailUpgrade mozilla-xulrunner192-translations-other-32bitUpgrade mozilla-xulrunner192-gnome-32bitUpgrade mozilla-xulrunner191-translations-32bitUpgrade mozilla-xulrunner192-32bitUpgrade mozilla-xulrunner191-translations-otherUpgrade mozilla-js192-32bitUpgrade mozilla-xulrunner191-translationsUpgrade mozilla-xulrunner191-translations-commonUpgrade mozillathunderbird-translations-commonUpgrade mozilla-xulrunner191-gnomevfs-32bitUpgrade MozillaThunderbird-develUpgrade mozilla-js192Upgrade seamonkey-venkmanUpgrade python-xpcom191Upgrade mozillafirefoxUpgrade mozilla-xulrunner191-32bitUpgrade mozilla-xulrunner192-translations-common-32bitUpgrade mozilla-xulrunner192 | Feb 17, 2015 | Aug 26, 2010 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub