CVE-2008-0304
published 2008-02-29CVE-2008-0304: Heap-based buffer overflow in Mozilla Thunderbird before 2.0.0.12 and SeaMonkey before 1.1.8 might allow remote attackers to execute arbitrary code via a…
PriorityP341high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
6.05%
92.6th percentile
Heap-based buffer overflow in Mozilla Thunderbird before 2.0.0.12 and SeaMonkey before 1.1.8 might allow remote attackers to execute arbitrary code via a crafted external-body MIME type in an e-mail message, related to an incorrect memory allocation during message preview.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | seamonkey | <= 1.1.7 | — |
| mozilla | thunderbird | <= 2.0.0.9 | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_ubuntu10.0CRITICAL
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3j5j-x7ph-c2r8: Heap-based buffer overflow in Mozilla Thunderbird before 2
ghsa_unreviewed·2022-05-01
CVE-2008-0304 [HIGH] CWE-119 GHSA-3j5j-x7ph-c2r8: Heap-based buffer overflow in Mozilla Thunderbird before 2
Heap-based buffer overflow in Mozilla Thunderbird before 2.0.0.12 and SeaMonkey before 1.1.8 might allow remote attackers to execute arbitrary code via a crafted external-body MIME type in an e-mail message, related to an incorrect memory allocation during message preview.
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2008-07-25·CVSS 10.0
CVE-2008-2785 [CRITICAL] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Thunderbird vulnerabilities
Various flaws were discovered in the browser engine. If a user had
Javascript enabled and were tricked into opening a malicious web
page, an attacker could cause a denial of service via application
crash, or possibly execute arbitrary code with the privileges of the
user invoking the program. (CVE-2008-2798, CVE-2008-2799)
It was discovered that Thunderbird would allow non-privileged XUL
documents to load chrome scripts from the fastload file if Javascript
was enabled. This could allow an attacker to execute arbitrary
Javascript code with chrome privileges. (CVE-2008-2802)
A flaw was discovered in Thunderbird that allowed overwriting trusted
objects via mozIJSSubScriptLoader.loadSubScript(). If a user had
Javascrip
Ubuntu
Thunderbird regression
vendor_ubuntu·2008-03-06·CVSS 7.5
[HIGH] Thunderbird regression
Title: Thunderbird regression
Summary: Thunderbird regression
USN-582-1 fixed several vulnerabilities in Thunderbird. The upstream
fixes were incomplete, and after performing certain actions Thunderbird
would crash due to memory errors. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that Thunderbird did not properly set the size of a
buffer when parsing an external-body MIME-type. If a user were to open
a specially crafted email, an attacker could cause a denial of service
via application crash or possibly execute arbitrary code as the user.
(CVE-2008-0304)
Various flaws were discovered in Thunderbird and its JavaScript
engine. By tricking a user into opening a malicious message, an
attacker could execute arbitrary code
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2008-02-29·CVSS 7.5
CVE-2008-0304 [HIGH] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Thunderbird vulnerabilities
It was discovered that Thunderbird did not properly set the size of a
buffer when parsing an external-body MIME-type. If a user were to open
a specially crafted email, an attacker could cause a denial of service
via application crash or possibly execute arbitrary code as the user.
(CVE-2008-0304)
Various flaws were discovered in Thunderbird and its JavaScript
engine. By tricking a user into opening a malicious message, an
attacker could execute arbitrary code with the user's privileges.
(CVE-2008-0412, CVE-2008-0413)
Various flaws were discovered in the JavaScript engine. By tricking
a user into opening a malicious message, an attacker could escalate
privileges within Thunderbird, perform cross-site scripting attac
Red Hat
thunderbird/seamonkey: MIME External-Body Heap Overflow Vulnerability
vendor_redhat·2008-02-26·CVSS 7.5
CVE-2008-0304 [HIGH] thunderbird/seamonkey: MIME External-Body Heap Overflow Vulnerability
thunderbird/seamonkey: MIME External-Body Heap Overflow Vulnerability
Heap-based buffer overflow in Mozilla Thunderbird before 2.0.0.12 and SeaMonkey before 1.1.8 might allow remote attackers to execute arbitrary code via a crafted external-body MIME type in an e-mail message, related to an incorrect memory allocation during message preview.
No detection rules found.
No public exploits indexed.
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=668http://secunia.com/advisories/29098http://secunia.com/advisories/29133http://secunia.com/advisories/29167http://secunia.com/advisories/29211http://secunia.com/advisories/30327http://secunia.com/advisories/31043http://secunia.com/advisories/31253http://secunia.com/advisories/33433http://securitytracker.com/id?1019504http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.445399http://sunsolve.sun.com/search/document.do?assetkey=1-26-239546-1http://www.debian.org/security/2008/dsa-1621http://www.debian.org/security/2009/dsa-1697http://www.gentoo.org/security/en/glsa/glsa-200805-18.xmlhttp://www.kb.cert.org/vuls/id/661651http://www.mandriva.com/security/advisories?name=MDVSA-2008:062http://www.mozilla.org/security/announce/2008/mfsa2008-12.htmlhttp://www.securityfocus.com/bid/28012http://www.ubuntu.com/usn/usn-582-1http://www.ubuntu.com/usn/usn-582-2http://www.vupen.com/english/advisories/2008/2091/referenceshttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11075https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00905.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-February/msg00946.htmlhttp://labs.idefense.com/intelligence/vulnerabilities/display.php?id=668http://secunia.com/advisories/29098http://secunia.com/advisories/29133http://secunia.com/advisories/29167http://secunia.com/advisories/29211http://secunia.com/advisories/30327http://secunia.com/advisories/31043http://secunia.com/advisories/31253http://secunia.com/advisories/33433http://securitytracker.com/id?1019504http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.445399http://sunsolve.sun.com/search/document.do?assetkey=1-26-239546-1http://www.debian.org/security/2008/dsa-1621http://www.debian.org/security/2009/dsa-1697http://www.gentoo.org/security/en/glsa/glsa-200805-18.xmlhttp://www.kb.cert.org/vuls/id/661651http://www.mandriva.com/security/advisories?name=MDVSA-2008:062http://www.mozilla.org/security/announce/2008/mfsa2008-12.htmlhttp://www.securityfocus.com/bid/28012http://www.ubuntu.com/usn/usn-582-1http://www.ubuntu.com/usn/usn-582-2http://www.vupen.com/english/advisories/2008/2091/referenceshttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11075https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00905.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-February/msg00946.html
2008-02-29
Published