7.5
CVSSv2

CVE-2008-0304

Published: 29/02/2008 Updated: 29/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Heap-based buffer overflow in Mozilla Thunderbird prior to 2.0.0.12 and SeaMonkey prior to 1.1.8 might allow remote malicious users to execute arbitrary code via a crafted external-body MIME type in an e-mail message, related to an incorrect memory allocation during message preview.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla seamonkey

mozilla thunderbird

Vendor Advisories

USN-582-1 fixed several vulnerabilities in Thunderbird The upstream fixes were incomplete, and after performing certain actions Thunderbird would crash due to memory errors This update fixes the problem ...
Various flaws were discovered in the browser engine If a user had Javascript enabled and were tricked into opening a malicious web page, an attacker could cause a denial of service via application crash, or possibly execute arbitrary code with the privileges of the user invoking the program (CVE-2008-2798, CVE-2008-2799) ...
It was discovered that Thunderbird did not properly set the size of a buffer when parsing an external-body MIME-type If a user were to open a specially crafted email, an attacker could cause a denial of service via application crash or possibly execute arbitrary code as the user (CVE-2008-0304) ...
Several remote vulnerabilities have been discovered in the Icedove mail client, an unbranded version of the Thunderbird client The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2008-0304 It was discovered that a buffer overflow in MIME decoding can lead to the execution of arbitrary code C ...
Several remote vulnerabilities have been discovered in Iceape an unbranded version of the Seamonkey internet suite The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2008-0016 Justin Schuh, Tom Cross and Peter Williams discovered a buffer overflow in the parser for UTF-8 URLs, which may lead to the ex ...
Mozilla Foundation Security Advisory 2008-12 Heap buffer overflow in external MIME bodies Announced February 26, 2008 Reporter regenrecht, iDefense Impact Critical Products SeaMonkey, Thunderbird Fixed in ...