4.3
CVSSv2

CVE-2010-0161

Published: 23/03/2010 Updated: 19/09/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

The nsAuthSSPI::Unwrap function in extensions/auth/nsAuthSSPI.cpp in Mozilla Thunderbird prior to 2.0.0.24 and SeaMonkey prior to 1.1.19 on Windows Vista, Windows Server 2008 R2, and Windows 7 allows remote SMTP, IMAP, and POP servers to cause a denial of service (heap memory corruption and application crash) or possibly execute arbitrary code via crafted data in a session that uses SSPI.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla thunderbird 2.0.0.16

mozilla thunderbird 2.0.0.18

mozilla thunderbird 2.0.0.17

mozilla thunderbird 2.0.0.6

mozilla thunderbird 2.0.0.5

mozilla thunderbird 2.0.0.14

mozilla thunderbird 2.0.0.4

mozilla thunderbird 2.0.0.0

mozilla thunderbird 1.5

mozilla thunderbird 1.5.0.3

mozilla thunderbird 1.5.0.14

mozilla thunderbird 1.5.0.11

mozilla thunderbird 1.0.3

mozilla thunderbird 1.0.2

mozilla thunderbird 0.7

mozilla thunderbird 0.6

mozilla thunderbird 1.5.2

mozilla thunderbird 1.5.1

mozilla thunderbird 1.5.0.13

mozilla thunderbird 1.5.0.10

mozilla thunderbird 1.0.5

mozilla thunderbird 1.0.4

mozilla thunderbird 0.7.2

mozilla thunderbird 0.7.1

mozilla thunderbird 0.1

mozilla thunderbird 2.0.0.21

mozilla thunderbird 2.0.0.19

mozilla thunderbird 2.0.0.8

mozilla thunderbird 2.0.0.7

mozilla thunderbird 1.5.0.9

mozilla thunderbird 1.5.0.8

mozilla thunderbird 1.5.0.7

mozilla thunderbird 1.5.0.1

mozilla thunderbird 1.0.7

mozilla thunderbird 1.0.6

mozilla thunderbird 0.8

mozilla thunderbird 0.7.3

mozilla thunderbird 0.3

mozilla thunderbird 0.2

mozilla thunderbird

mozilla thunderbird 2.0.0.22

mozilla thunderbird 2.0.0.12

mozilla thunderbird 2.0.0.9

mozilla thunderbird 1.5.0.12

mozilla thunderbird 1.5.0.5

mozilla thunderbird 1.5.0.4

mozilla thunderbird 1.5.0.6

mozilla thunderbird 1.5.0.2

mozilla thunderbird 1.0.8

mozilla thunderbird 1.0.1

mozilla thunderbird 1.0

mozilla thunderbird 0.9

mozilla thunderbird 0.5

mozilla thunderbird 0.4

mozilla seamonkey

mozilla seamonkey 1.1.11

mozilla seamonkey 1.1.10

mozilla seamonkey 1.1.9

mozilla seamonkey 1.1.2

mozilla seamonkey 1.1.1

mozilla seamonkey 1.0.6

mozilla seamonkey 1.0.5

mozilla seamonkey 1.1.13

mozilla seamonkey 1.1.12

mozilla seamonkey 1.1.4

mozilla seamonkey 1.1.3

mozilla seamonkey 1.0.8

mozilla seamonkey 1.0.7

mozilla seamonkey 1.0

mozilla seamonkey 1.1.15

mozilla seamonkey 1.1.14

mozilla seamonkey 1.1.6

mozilla seamonkey 1.1.5

mozilla seamonkey 1.1

mozilla seamonkey 1.0.9

mozilla seamonkey 1.0.2

mozilla seamonkey 1.0.1

mozilla seamonkey 1.1.17

mozilla seamonkey 1.1.16

mozilla seamonkey 1.1.8

mozilla seamonkey 1.1.7

mozilla seamonkey 1.0.4

mozilla seamonkey 1.0.3

Vendor Advisories

Mozilla Foundation Security Advisory 2010-07 Fixes for potentially exploitable crashes ported to the legacy branch Announced March 16, 2010 Reporter Mozilla developers and community Impact Critical Products SeaMonkey, Thunder ...