10
CVSSv2

CVE-2008-4070

Published: 27/09/2008 Updated: 29/09/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Heap-based buffer overflow in Mozilla Thunderbird prior to 2.0.0.17 and SeaMonkey prior to 1.1.12 allows remote malicious users to cause a denial of service (application crash) or possibly execute arbitrary code via a long header in a news article, related to "canceling [a] newsgroup message" and "cancelled newsgroup messages."

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla thunderbird 2.0.0.1

mozilla thunderbird 2.0.0.12

mozilla thunderbird 2.0.0.4

mozilla thunderbird 1.0.4

mozilla thunderbird 2.0.0.11

mozilla thunderbird 1.5.0.10

mozilla thunderbird 1.5.0.11

mozilla thunderbird 0.7.2

mozilla thunderbird 0.7.3

mozilla thunderbird 0.9

mozilla thunderbird 0.1

mozilla thunderbird 2.0.0.5

mozilla thunderbird 2.0.0.6

mozilla thunderbird 2.0.0.9

mozilla seamonkey 1.0.9

mozilla seamonkey 1.0.8

mozilla seamonkey 1.0.5

mozilla seamonkey 1.0.4

mozilla thunderbird 1.5.0.9

mozilla thunderbird 1.5.0.8

mozilla thunderbird 1.0.8

mozilla thunderbird 1.5

mozilla thunderbird 1.5.0.4

mozilla thunderbird 1.5.0.6

mozilla thunderbird 2.0.0.14

mozilla thunderbird 2.0.0.13

mozilla thunderbird 1.0

mozilla thunderbird 0.6

mozilla thunderbird 0.3

mozilla seamonkey 1.1.10

mozilla seamonkey 1.0

mozilla seamonkey 1.1.2

mozilla thunderbird 1.5.2

mozilla thunderbird 1.5.1

mozilla thunderbird 1.0.2

mozilla thunderbird 1.0.3

mozilla thunderbird 1.5.0.7

mozilla thunderbird 1.5.0.1

mozilla thunderbird 1.7.1

mozilla thunderbird 1.7.3

mozilla thunderbird 1.0.1

mozilla thunderbird 0.8

mozilla thunderbird 0.4

mozilla thunderbird

mozilla seamonkey 1.0.1

mozilla seamonkey 1.1

mozilla seamonkey 1.0.99

mozilla seamonkey

mozilla thunderbird 2.0.0.0

mozilla thunderbird 2.0.0.3

mozilla thunderbird 2.0.0.2

mozilla thunderbird 1.0.6

mozilla thunderbird 1.0.7

mozilla thunderbird 1.0.5

mozilla thunderbird 1.5.0.3

mozilla thunderbird 1.5.0.2

mozilla thunderbird 2.0.0.15

mozilla thunderbird 0.7

mozilla thunderbird 0.7.1

mozilla thunderbird 0.2

mozilla thunderbird 0.5

mozilla thunderbird 2.0.0.7

mozilla seamonkey 1.1.1

mozilla seamonkey 1.0.7

mozilla seamonkey 1.0.6

mozilla seamonkey 1.0.3

mozilla seamonkey 1.0.2

Vendor Advisories

Synopsis Moderate: thunderbird security update Type/Severity Security Advisory: Moderate Topic Updated thunderbird packages that fix several security issues are nowavailable for Red Hat Enterprise Linux 4 and 5This update has been rated as having moderate security impact by the RedHat Security Response Tea ...
It was discovered that the same-origin check in Thunderbird could be bypassed If a user had JavaScript enabled and were tricked into opening a malicious website, an attacker may be able to execute JavaScript in the context of a different website (CVE-2008-3835) ...
Several remote vulnerabilities have been discovered in Iceape an unbranded version of the Seamonkey internet suite The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2008-0016 Justin Schuh, Tom Cross and Peter Williams discovered a buffer overflow in the parser for UTF-8 URLs, which may lead to the ex ...
Mozilla Foundation Security Advisory 2008-46 Heap overflow when canceling newsgroup message Announced September 25, 2008 Reporter Georgi Guninski Impact Critical Products SeaMonkey, Thunderbird Fixed in ...