5
CVSSv2

CVE-2005-0255

Published: 02/05/2005 Updated: 11/10/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

String handling functions in Mozilla 1.7.3, Firefox 1.0, and Thunderbird prior to 1.0.2, such as the nsTSubstring_CharT::Replace function, do not properly check the return values of other functions that resize the string, which allows remote malicious users to cause a denial of service and possibly execute arbitrary code by forcing an out-of-memory state that causes a reallocation to fail and return a pointer to a fixed address, which leads to heap corruption.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla thunderbird 0.1

mozilla thunderbird 0.2

mozilla firefox 1.0

mozilla mozilla 1.7.3

mozilla thunderbird 0.7

mozilla thunderbird 0.8

mozilla thunderbird 0.3

mozilla thunderbird 0.4

mozilla thunderbird 0.9

mozilla thunderbird 1.0

mozilla thunderbird 0.5

mozilla thunderbird 0.6

Vendor Advisories

USN-149-1 fixed some vulnerabilities in the Ubuntu 504 (Hoary Hedgehog) version of Firefox The version shipped with Ubuntu 410 (Warty Warthog) is also vulnerable to these flaws, so it needs to be upgraded as well Please see ...
Synopsis firefox security update Type/Severity Security Advisory: Critical Topic Updated firefox packages that fix various bugs are now availableThis update has been rated as having critical security impact by the RedHat Security Response Team Description Mozilla Firefox is an open source ...
Synopsis mozilla security update Type/Severity Security Advisory: Critical Topic Updated mozilla packages that fix a buffer overflow issue are now availableThis update has been rated as having critical security impact by the RedHat Security Response Team Description Mozilla is an open sou ...
Synopsis thunderbird security update Type/Severity Security Advisory: Critical Topic Updated thunderbird packages that fix various bugs are now availableThis update has been rated as having critical security impact by the RedHat Security Response Team Description Mozilla Thunderbird is a ...