CVE-2007-1282
published 2007-03-06CVE-2007-1282: Integer overflow in Mozilla Thunderbird before 1.5.0.10 and SeaMonkey before 1.0.8 allows remote attackers to trigger a buffer overflow and possibly execute…
PriorityP335critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
4.69%
90.8th percentile
Integer overflow in Mozilla Thunderbird before 1.5.0.10 and SeaMonkey before 1.0.8 allows remote attackers to trigger a buffer overflow and possibly execute arbitrary code via a text/enhanced or text/richtext e-mail message with an extremely long line.
Affected
38 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | thunderbird | — | — |
| mozilla | thunderbird | — | — |
| mozilla | thunderbird | — | — |
| mozilla | thunderbird | — | — |
| mozilla | thunderbird | — | — |
| mozilla | thunderbird | — | — |
| mozilla | thunderbird | — | — |
| mozilla | thunderbird | — | — |
| mozilla | thunderbird | — | — |
| mozilla | thunderbird | — | — |
| mozilla | thunderbird | — | — |
| mozilla | thunderbird | — | — |
| mozilla | thunderbird | — | — |
| mozilla | thunderbird | — | — |
| mozilla | thunderbird | — | — |
| mozilla | thunderbird | — | — |
| mozilla | thunderbird | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-rc8w-53vr-5ppv: Integer overflow in Mozilla Thunderbird before 1
ghsa_unreviewed·2022-05-03
CVE-2007-1282 [HIGH] GHSA-rc8w-53vr-5ppv: Integer overflow in Mozilla Thunderbird before 1
Integer overflow in Mozilla Thunderbird before 1.5.0.10 and SeaMonkey before 1.0.8 allows remote attackers to trigger a buffer overflow and possibly execute arbitrary code via a text/enhanced or text/richtext e-mail message with an extremely long line.
Red Hat
security flaw
vendor_redhat·2007-03-05·CVSS 9.3
CVE-2007-1282 [CRITICAL] security flaw
security flaw
Integer overflow in Mozilla Thunderbird before 1.5.0.10 and SeaMonkey before 1.0.8 allows remote attackers to trigger a buffer overflow and possibly execute arbitrary code via a text/enhanced or text/richtext e-mail message with an extremely long line.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2007-1282 security flaw
bugzilla·2018-08-16·CVSS 9.3
CVE-2007-1282 [CRITICAL] CVE-2007-1282 security flaw
CVE-2007-1282 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
Integer overflow in Mozilla Thunderbird before 1.5.0.10 and SeaMonkey before 1.0.8 allows remote attackers to trigger a buffer overflow and possibly execute arbitrary code via a text/enhanced or text/richtext e-mail message with an extremely long line.
Bugzilla
CVE-2007-0775 Multiple Thunderbird flaws (CVE-2007-0777, CVE-2007-0995, CVE-2007-0996, CVE-2006-6077, CVE-2007-0778, CVE-2007-0779, CVE-2007-0780, CVE-2007-0800, CVE-2007-0008, CVE-2007-0009, CVE-2007
bugzilla·2007-03-01·CVSS 5.0
CVE-2007-0775 [MEDIUM] CVE-2007-0775 Multiple Thunderbird flaws (CVE-2007-0777, CVE-2007-0995, CVE-2007-0996, CVE-2006-6077, CVE-2007-0778, CVE-2007-0779, CVE-2007-0780, CVE-2007-0800, CVE-2007-0008, CVE-2007-0009, CVE-2007
CVE-2007-0775 Multiple Thunderbird flaws (CVE-2007-0777, CVE-2007-0995, CVE-2007-0996, CVE-2006-6077, CVE-2007-0778, CVE-2007-0779, CVE-2007-0780, CVE-2007-0800, CVE-2007-0008, CVE-2007-0009, CVE-2007-0981, CVE-2007-1282)
+++ This bug was initially created as a clone of Bug #230542 +++
The Mozilla project is releasing Thunderbird 1.5.0.10 to fix several flaws:
mfsa2007-01
impact=moderate,source=mozilla,reported=20070222,public=20070223
CVE-2007-0775
Jesse Ruderman, Martijn Wargers and Olli Pettay reported crashes in the
layout engine
CVE-2007-0777
Brian Crowder, Igor Bukanov, Johnny Stenback, moz_bug_r_a4 and shutdown
reported potential memory corruption in the JavaScript engine
mfsa2007-02
impact=moderate,source=mozilla,reported=20070222,public=20070223
CVE-2007-0995
The Mozilla pa
ftp://patches.sgi.com/support/free/security/advisories/20070202-01-P.aschttp://fedoranews.org/cms/node/2747http://fedoranews.org/cms/node/2749http://osvdb.org/33810http://secunia.com/advisories/24406http://secunia.com/advisories/24456http://secunia.com/advisories/24457http://secunia.com/advisories/24522http://secunia.com/advisories/25588http://security.gentoo.org/glsa/glsa-200703-18.xmlhttp://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.338131http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.363947http://www.debian.org/security/2007/dsa-1336http://www.mozilla.org/security/announce/2007/mfsa2007-10.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0078.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0108.htmlhttp://www.securityfocus.com/bid/22845http://www.vupen.com/english/advisories/2007/0824https://bugzilla.mozilla.org/show_bug.cgi?id=362735https://exchange.xforce.ibmcloud.com/vulnerabilities/32810https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11313ftp://patches.sgi.com/support/free/security/advisories/20070202-01-P.aschttp://fedoranews.org/cms/node/2747http://fedoranews.org/cms/node/2749http://osvdb.org/33810http://secunia.com/advisories/24406http://secunia.com/advisories/24456http://secunia.com/advisories/24457http://secunia.com/advisories/24522http://secunia.com/advisories/25588http://security.gentoo.org/glsa/glsa-200703-18.xmlhttp://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.338131http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.363947http://www.debian.org/security/2007/dsa-1336http://www.mozilla.org/security/announce/2007/mfsa2007-10.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0078.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0108.htmlhttp://www.securityfocus.com/bid/22845http://www.vupen.com/english/advisories/2007/0824https://bugzilla.mozilla.org/show_bug.cgi?id=362735https://exchange.xforce.ibmcloud.com/vulnerabilities/32810https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11313
2007-03-06
Published