CVE-2007-1282Improper Restriction of Operations within the Bounds of a Memory Buffer in Mozilla Seamonkey

5 documents4 sources
Severity
9.3CRITICALNVD
EPSS
3.4%
top 12.51%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 6
Latest updateMay 3

Description

Integer overflow in Mozilla Thunderbird before 1.5.0.10 and SeaMonkey before 1.0.8 allows remote attackers to trigger a buffer overflow and possibly execute arbitrary code via a text/enhanced or text/richtext e-mail message with an extremely long line.

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages2 packages

NVDmozilla/seamonkey8 versions+7
NVDmozilla/thunderbird30 versions+29

Patches

🔴Vulnerability Details

1
GHSA
GHSA-rc8w-53vr-5ppv: Integer overflow in Mozilla Thunderbird before 12022-05-03

📋Vendor Advisories

1
Red Hat
security flaw2007-03-05

💬Community

2
Bugzilla
CVE-2007-1282 security flaw2018-08-16
Bugzilla
CVE-2007-0775 Multiple Thunderbird flaws (CVE-2007-0777, CVE-2007-0995, CVE-2007-0996, CVE-2006-6077, CVE-2007-0778, CVE-2007-0779, CVE-2007-0780, CVE-2007-0800, CVE-2007-0008, CVE-2007-0009, CVE-20072007-03-01