9.3
CVSSv2

CVE-2008-0420

Published: 12/02/2008 Updated: 15/10/2018
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

modules/libpr0n/decoders/bmp/nsBMPDecoder.cpp in Mozilla Firefox prior to 2.0.0.12, Thunderbird prior to 2.0.0.12, and SeaMonkey prior to 1.1.8 does not properly perform certain calculations related to the mColors table, which allows remote malicious users to read portions of memory uninitialized via a crafted 8-bit bitmap (BMP) file that triggers an out-of-bounds read within the heap, as demonstrated using a CANVAS element; or cause a denial of service (application crash) via a crafted 8-bit bitmap file that triggers an out-of-bounds read. NOTE: the initial public reports stated that this affected Firefox in Ubuntu 6.06 up to and including 7.10.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla thunderbird

mozilla firefox 2.0.0.10

mozilla firefox 1.5.0.10

mozilla firefox 1.5.0.9

mozilla firefox 1.0.8

mozilla firefox 1.0.5

mozilla firefox 0.9

mozilla firefox 0.8

mozilla firefox 0.2

mozilla firefox 0.1

mozilla thunderbird 1.5.0.7

mozilla thunderbird 1.5.0.14

mozilla thunderbird 1.0.6

mozilla thunderbird 1.0.5

mozilla thunderbird 1.0.2

mozilla thunderbird 0.1

mozilla thunderbird 1.5.0.5

mozilla seamonkey 1.0.8

mozilla seamonkey 1.0.6

mozilla firefox 2.0.0.2

mozilla firefox 2.0.0.1

mozilla firefox 1.5.0.4

mozilla firefox 1.5.0.2

mozilla firefox 1.0

mozilla firefox 0.9.3

mozilla firefox 0.6

mozilla firefox 0.5

mozilla thunderbird 2.0.0.4

mozilla thunderbird 2.0.0.5

mozilla thunderbird 1.5.0.4

mozilla thunderbird 1.5.0.2

mozilla thunderbird 0.8

mozilla thunderbird 0.7

mozilla seamonkey 1.1.1

mozilla seamonkey 1.1

mozilla seamonkey 1.0.5

mozilla seamonkey 1.0.3

mozilla firefox 2.0.0.9

mozilla firefox 2.0.0.8

mozilla firefox 2.0.0.7

mozilla firefox 1.5.0.7

mozilla firefox 1.5.0.6

mozilla firefox 1.0.3

mozilla firefox 0.7.1

mozilla firefox 0.7

mozilla firefox 0.6.1

mozilla thunderbird 2.0.0.9

mozilla thunderbird 2.0.0.6

mozilla thunderbird 1.5.0.13

mozilla thunderbird 1.5.0.12

mozilla thunderbird 1.0

mozilla thunderbird 0.9

mozilla seamonkey 1.1.6

mozilla seamonkey 1.1.2

mozilla seamonkey 1.0.7

mozilla seamonkey 1.0

mozilla firefox

mozilla seamonkey

mozilla firefox 2.0

mozilla firefox 1.5.0.12

mozilla firefox 1.5.0.1

mozilla firefox 1.5

mozilla firefox 0.9.2

mozilla firefox 0.9.1

mozilla firefox 0.4

mozilla firefox 0.3

mozilla thunderbird 2.0.0.0

mozilla thunderbird 1.5.0.9

mozilla thunderbird 1.5

mozilla thunderbird 1.0.8

mozilla thunderbird 0.6

mozilla thunderbird 0.5

mozilla seamonkey 1.0.9

mozilla seamonkey 1.0.2

mozilla seamonkey 1.0.1

Vendor Advisories

USN-582-1 fixed several vulnerabilities in Thunderbird The upstream fixes were incomplete, and after performing certain actions Thunderbird would crash due to memory errors This update fixes the problem ...
Various flaws were discovered in the browser and JavaScript engine By tricking a user into opening a malicious web page, an attacker could execute arbitrary code with the user’s privileges (CVE-2008-0412, CVE-2008-0413) ...
It was discovered that Thunderbird did not properly set the size of a buffer when parsing an external-body MIME-type If a user were to open a specially crafted email, an attacker could cause a denial of service via application crash or possibly execute arbitrary code as the user (CVE-2008-0304) ...
Mozilla Foundation Security Advisory 2008-07 Possible information disclosure in BMP decoder Announced February 19, 2008 Reporter Gynvael Coldwind // Vexillium Impact Moderate Products Firefox, SeaMonkey Fixed in ...