HIGH
Integer overflow in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, and SeaMonkey before 2.0.6 allows remote attackers to execute arbitrary code via a large selection attribute in a XUL tree element, which triggers a use-after-free.
http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00002.html
http://www.mozilla.org/security/announce/2010/mfsa2010-40.html
http://www.securityfocus.com/archive/1/512510
http://www.securityfocus.com/bid/41853
http://www.zerodayinitiative.com/advisories/ZDI-10-131/
https://bugzilla.mozilla.org/show_bug.cgi?id=571106
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10958
OR
cpe:2.3:a:mozilla:firefox:3.5.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:3.5.2:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:3.5.3:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:3.5.4:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:3.5.5:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:3.5.6:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:3.5.7:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:3.5.9:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:3.5.10:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:3.6.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:3.6.2:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:3.6.3:*:*:*:*:*:*:*
OR
cpe:2.3:a:mozilla:seamonkey:1.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:1.0:alpha:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:1.0:beta:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:1.0.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:1.0.2:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:1.0.3:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:1.0.4:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:1.0.5:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:1.0.6:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:1.0.7:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:1.0.8:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:1.0.9:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:1.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:1.1:alpha:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:1.1:beta:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:1.1.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:1.1.2:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:1.1.3:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:1.1.4:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:1.1.5:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:1.1.6:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:1.1.7:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:1.1.8:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:1.1.9:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:1.1.10:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:1.1.11:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:1.1.12:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:1.1.13:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:1.1.14:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:1.1.15:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:1.1.16:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:1.1.17:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:1.1.18:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:1.1.19:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:1.5.0.8:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:1.5.0.9:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:1.5.0.10:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.0:alpha_1:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.0:alpha_2:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.0:alpha_3:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.0:beta_1:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.0:beta_2:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.0:rc1:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.0:rc2:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.0.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.0.2:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.0.3:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.0.4:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:* versions up to 2.0.5 (inclusive)
OR
cpe:2.3:a:mozilla:thunderbird:3.0.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:3.0.2:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:3.0.3:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:3.0.4:*:*:*:*:*:*:*
ID | Name | Product | Family | Severity |
---|---|---|---|---|
75733 | openSUSE Security Update : seamonkey (seamonkey-3372) | Nessus | SuSE Local Security Checks | high |
75732 | openSUSE Security Update : seamonkey (openSUSE-SU-2010:0632-2) | Nessus | SuSE Local Security Checks | high |
75731 | openSUSE Security Update : seamonkey (openSUSE-SU-2010:0430-1) | Nessus | SuSE Local Security Checks | high |
75671 | openSUSE Security Update : mozilla-xulrunner191 (mozilla-xulrunner191-3421) | Nessus | SuSE Local Security Checks | high |
75670 | openSUSE Security Update : mozilla-xulrunner191 (mozilla-xulrunner191-3141) | Nessus | SuSE Local Security Checks | high |
75669 | openSUSE Security Update : mozilla-xulrunner191 (mozilla-xulrunner191-2779) | Nessus | SuSE Local Security Checks | high |
75660 | openSUSE Security Update : MozillaThunderbird (MozillaThunderbird-3378) | Nessus | SuSE Local Security Checks | high |
75659 | openSUSE Security Update : MozillaThunderbird (MozillaThunderbird-3154) | Nessus | SuSE Local Security Checks | high |
75658 | openSUSE Security Update : MozillaThunderbird (openSUSE-SU-2010:0430-2) | Nessus | SuSE Local Security Checks | high |
75647 | openSUSE Security Update : MozillaFirefox (openSUSE-SU-2010:0632-1) | Nessus | SuSE Local Security Checks | high |
75646 | openSUSE Security Update : MozillaFirefox (MozillaFirefox-2807) | Nessus | SuSE Local Security Checks | critical |
68099 | Oracle Linux 4 : thunderbird (ELSA-2010-0682) | Nessus | Oracle Linux Local Security Checks | high |
68098 | Oracle Linux 4 / 5 : firefox (ELSA-2010-0681) | Nessus | Oracle Linux Local Security Checks | high |
68097 | Oracle Linux 3 / 4 : seamonkey (ELSA-2010-0680) | Nessus | Oracle Linux Local Security Checks | high |
68068 | Oracle Linux 4 / 5 : firefox (ELSA-2010-0547) | Nessus | Oracle Linux Local Security Checks | high |
68067 | Oracle Linux 3 / 4 : seamonkey (ELSA-2010-0546) | Nessus | Oracle Linux Local Security Checks | high |
68066 | Oracle Linux 4 : thunderbird (ELSA-2010-0544) | Nessus | Oracle Linux Local Security Checks | critical |
63939 | RHEL 5 : thunderbird (RHSA-2010:0545) | Nessus | Red Hat Local Security Checks | critical |
63402 | GLSA-201301-01 : Mozilla Products: Multiple vulnerabilities (BEAST) | Nessus | Gentoo Local Security Checks | critical |
60822 | Scientific Linux Security Update : thunderbird on SL5.x i386/x86_64 | Nessus | Scientific Linux Local Security Checks | critical |
60821 | Scientific Linux Security Update : thunderbird on SL4.x i386/x86_64 | Nessus | Scientific Linux Local Security Checks | critical |
60820 | Scientific Linux Security Update : seamonkey on SL3.x, SL4.x i386/x86_64 | Nessus | Scientific Linux Local Security Checks | high |
60818 | Scientific Linux Security Update : firefox on SL4.x, SL5.x i386/x86_64 | Nessus | Scientific Linux Local Security Checks | high |
53540 | RHEL 4 / 5 : firefox (RHSA-2010:0681) | Nessus | Red Hat Local Security Checks | high |
50951 | SuSE 11 / 11.1 Security Update : Mozilla (SAT Patch Numbers 3417 / 3419) | Nessus | SuSE Local Security Checks | high |
50875 | SuSE 11 / 11.1 Security Update : Mozilla Firefox (SAT Patch Numbers 3159 / 3160) | Nessus | SuSE Local Security Checks | high |
50874 | SuSE 11 / 11.1 Security Update : Mozilla Firefox (SAT Patch Numbers 2780 / 2781) | Nessus | SuSE Local Security Checks | high |
50488 | SuSE 10 Security Update : Mozilla Firefox (ZYPP Patch Number 7208) | Nessus | SuSE Local Security Checks | high |
50466 | openSUSE Security Update : mozilla-xulrunner191 (mozilla-xulrunner191-3421) | Nessus | SuSE Local Security Checks | high |
50462 | openSUSE Security Update : mozilla-xulrunner191 (mozilla-xulrunner191-3421) | Nessus | SuSE Local Security Checks | high |
50376 | openSUSE Security Update : seamonkey (seamonkey-3372) | Nessus | SuSE Local Security Checks | high |
50372 | openSUSE Security Update : MozillaThunderbird (MozillaThunderbird-3378) | Nessus | SuSE Local Security Checks | high |
50371 | openSUSE Security Update : seamonkey (seamonkey-3372) | Nessus | SuSE Local Security Checks | high |
50366 | openSUSE Security Update : MozillaThunderbird (MozillaThunderbird-3378) | Nessus | SuSE Local Security Checks | high |
49947 | openSUSE Security Update : mozilla-xulrunner191 (mozilla-xulrunner191-3141) | Nessus | SuSE Local Security Checks | high |
49946 | openSUSE Security Update : MozillaThunderbird (MozillaThunderbird-3154) | Nessus | SuSE Local Security Checks | high |
49945 | openSUSE Security Update : mozilla-xulrunner191 (mozilla-xulrunner191-3141) | Nessus | SuSE Local Security Checks | high |
49944 | openSUSE Security Update : MozillaThunderbird (MozillaThunderbird-3154) | Nessus | SuSE Local Security Checks | high |
49894 | SuSE 10 Security Update : Mozilla Firefox (ZYPP Patch Number 7101) | Nessus | SuSE Local Security Checks | high |
49282 | openSUSE Security Update : seamonkey (openSUSE-SU-2010:0632-2) | Nessus | SuSE Local Security Checks | high |
49281 | openSUSE Security Update : MozillaFirefox (openSUSE-SU-2010:0632-1) | Nessus | SuSE Local Security Checks | high |
49280 | openSUSE Security Update : seamonkey (openSUSE-SU-2010:0632-2) | Nessus | SuSE Local Security Checks | high |
49279 | openSUSE Security Update : MozillaFirefox (openSUSE-SU-2010:0632-1) | Nessus | SuSE Local Security Checks | high |
49183 | CentOS 4 / 5 : thunderbird (CESA-2010:0682) | Nessus | CentOS Local Security Checks | high |
49182 | CentOS 4 / 5 : firefox (CESA-2010:0681) | Nessus | CentOS Local Security Checks | high |
49181 | CentOS 3 / 4 : seamonkey (CESA-2010:0680) | Nessus | CentOS Local Security Checks | high |
49170 | Ubuntu 10.04 LTS : thunderbird vulnerabilities (USN-978-1) | Nessus | Ubuntu Local Security Checks | high |
49169 | Ubuntu 8.04 LTS / 9.04 / 9.10 / 10.04 LTS : firefox, firefox-3.0, firefox-3.5, xulrunner-1.9.1, xulrunner-1.9.2 vulnerabilities (USN-975-1) | Nessus | Ubuntu Local Security Checks | high |
49133 | RHEL 4 / 5 : thunderbird (RHSA-2010:0682) | Nessus | Red Hat Local Security Checks | high |
49132 | RHEL 3 / 4 : seamonkey (RHSA-2010:0680) | Nessus | Red Hat Local Security Checks | high |
49099 | Mandriva Linux Security Advisory : mozilla-thunderbird (MDVSA-2010:169) | Nessus | Mandriva Local Security Checks | high |
48342 | CentOS 3 : seamonkey (CESA-2010:0546) | Nessus | CentOS Local Security Checks | high |
48266 | CentOS 4 : thunderbird (CESA-2010:0544) | Nessus | CentOS Local Security Checks | critical |
47907 | openSUSE Security Update : MozillaFirefox (openSUSE-SU-2010:0430-3) | Nessus | SuSE Local Security Checks | high |
47906 | openSUSE Security Update : MozillaFirefox (openSUSE-SU-2010:0430-3) | Nessus | SuSE Local Security Checks | high |
47889 | Debian DSA-2075-1 : xulrunner - several vulnerabilities | Nessus | Debian Local Security Checks | high |
47881 | RHEL 4 / 5 : firefox (RHSA-2010:0547) | Nessus | Red Hat Local Security Checks | high |
47880 | RHEL 3 / 4 : seamonkey (RHSA-2010:0546) | Nessus | Red Hat Local Security Checks | high |
47879 | RHEL 4 : thunderbird (RHSA-2010:0544) | Nessus | Red Hat Local Security Checks | critical |
47868 | openSUSE Security Update : MozillaThunderbird (openSUSE-SU-2010:0430-2) | Nessus | SuSE Local Security Checks | high |
47857 | Ubuntu 10.04 LTS : thunderbird vulnerabilities (USN-958-1) | Nessus | Ubuntu Local Security Checks | high |
47856 | Ubuntu 8.04 LTS / 10.04 LTS : firefox, firefox-3.0, xulrunner-1.9.2 vulnerability (USN-957-2) | Nessus | Ubuntu Local Security Checks | critical |
47854 | openSUSE Security Update : seamonkey (openSUSE-SU-2010:0430-1) | Nessus | SuSE Local Security Checks | high |
47826 | Ubuntu 8.04 LTS / 10.04 LTS : firefox, firefox-3.0, xulrunner-1.9.2 vulnerabilities (USN-957-1) | Nessus | Ubuntu Local Security Checks | high |
47825 | Ubuntu 9.04 / 9.10 : ant, apturl, epiphany-browser, gluezilla, gnome-python-extras, liferea, mozvoikko, openjdk-6, packagekit, ubufox, webfav, yelp update (USN-930-5) | Nessus | Ubuntu Local Security Checks | critical |
47824 | Ubuntu 9.04 / 9.10 : firefox-3.0, firefox-3.5, xulrunner-1.9.2 vulnerabilities (USN-930-4) | Nessus | Ubuntu Local Security Checks | critical |
47813 | Fedora 13 : sunbird-1.0-0.26.b2pre.fc13 / thunderbird-3.1.1-1.fc13 (2010-11379) | Nessus | Fedora Local Security Checks | high |
47812 | Fedora 12 : firefox-3.5.11-1.fc12 / galeon-2.0.7-24.fc12 / gnome-python2-extras-2.25.3-19.fc12 / etc (2010-11375) | Nessus | Fedora Local Security Checks | high |
47811 | Fedora 12 : seamonkey-2.0.6-1.fc12 (2010-11363) | Nessus | Fedora Local Security Checks | high |
47810 | Fedora 12 : sunbird-1.0-0.23.20090916hg.fc12 / thunderbird-3.0.6-1.fc12 (2010-11361) | Nessus | Fedora Local Security Checks | critical |
47809 | Fedora 13 : firefox-3.6.7-1.fc13 / galeon-2.0.7-30.fc13 / gnome-python2-extras-2.25.3-20.fc13 / etc (2010-11345) | Nessus | Fedora Local Security Checks | high |
47807 | Fedora 13 : seamonkey-2.0.6-1.fc13 (2010-11327) | Nessus | Fedora Local Security Checks | high |
47806 | CentOS 4 / 5 : firefox (CESA-2010:0547) | Nessus | CentOS Local Security Checks | high |
47805 | CentOS 5 : thunderbird (CESA-2010:0545) | Nessus | CentOS Local Security Checks | critical |
47794 | FreeBSD : mozilla -- multiple vulnerabilities (8c2ea875-9499-11df-8e32-000f20797ede) | Nessus | FreeBSD Local Security Checks | high |
47782 | Firefox 3.6 < 3.6.7 Multiple Vulnerabilities | Nessus | Windows | high |
47781 | Firefox < 3.5.11 Multiple Vulnerabilities | Nessus | Windows | high |
800871 | SeaMonkey 2.0.x < 2.0.6 Multiple Vulnerabilities | Log Correlation Engine | Web Clients | high |
800782 | Firefox 3.5.x < 3.5.11 Multiple Vulnerabilities | Log Correlation Engine | Web Clients | high |
800780 | Firefox 3.6.x < 3.6.7 Multiple Vulnerabilities | Log Correlation Engine | Web Clients | high |
47785 | SeaMonkey < 2.0.6 Multiple Vulnerabilities | Nessus | Windows | high |
47784 | Mozilla Thunderbird 3.1.x < 3.1.1 Multiple Vulnerabilities | Nessus | Windows | high |
47783 | Mozilla Thunderbird < 3.0.6 Multiple Vulnerabilities | Nessus | Windows | high |
5610 | SeaMonkey 2.0.x < 2.0.6 Multiple Vulnerabilities | Nessus Network Monitor | Web Clients | medium |
5609 | Mozilla Thunderbird 3.1.x < 3.1.1 Multiple Vulnerabilities | Nessus Network Monitor | SMTP Clients | medium |
5608 | Mozilla Thunderbird 3.0.x < 3.0.6 Multiple Vulnerabilities | Nessus Network Monitor | SMTP Clients | medium |
5607 | Mozilla Firefox 3.6.x < 3.6.7 Multiple Vulnerabilities | Nessus Network Monitor | Web Clients | medium |
5606 | Mozilla Firefox 3.5.x < 3.5.11 Multiple Vulnerabilities | Nessus Network Monitor | Web Clients | medium |