CVE-2008-4070
published 2008-09-27CVE-2008-4070: Heap-based buffer overflow in Mozilla Thunderbird before 2.0.0.17 and SeaMonkey before 1.1.12 allows remote attackers to cause a denial of service (application…
PriorityP343critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
7.35%
93.7th percentile
Heap-based buffer overflow in Mozilla Thunderbird before 2.0.0.17 and SeaMonkey before 1.1.12 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long header in a news article, related to "canceling [a] newsgroup message" and "cancelled newsgroup messages."
Affected
67 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | seamonkey | <= 1.1.11 | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | thunderbird | <= 2.0.0.16 | — |
| mozilla | thunderbird | — | — |
| mozilla | thunderbird | — | — |
| mozilla | thunderbird | — | — |
| mozilla | thunderbird | — | — |
| mozilla | thunderbird | — | — |
| mozilla | thunderbird | — | — |
| mozilla | thunderbird | — | — |
| mozilla | thunderbird | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat10.0CRITICAL
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2008-09-26·CVSS 7.5
CVE-2008-4067 [HIGH] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Thunderbird vulnerabilities
It was discovered that the same-origin check in Thunderbird could
be bypassed. If a user had JavaScript enabled and were tricked into
opening a malicious website, an attacker may be able to execute
JavaScript in the context of a different website. (CVE-2008-3835)
Several problems were discovered in the browser engine of
Thunderbird. If a user had JavaScript enabled, this could allow an
attacker to execute code with chrome privileges. (CVE-2008-4058,
CVE-2008-4059, CVE-2008-4060)
Drew Yao, David Maciejak and other Mozilla developers found several
problems in the browser engine of Thunderbird. If a user had
JavaScript enabled and were tricked into opening a malicious web
page, an attacker could cause a denial of serv
Red Hat
Thunderbird cancelled newsgrop messages
vendor_redhat·2008-09-25·CVSS 10.0
CVE-2008-4070 [CRITICAL] Thunderbird cancelled newsgrop messages
Thunderbird cancelled newsgrop messages
Heap-based buffer overflow in Mozilla Thunderbird before 2.0.0.17 and SeaMonkey before 1.1.12 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long header in a news article, related to "canceling [a] newsgroup message" and "cancelled newsgroup messages."
GHSA
GHSA-47xq-mwq7-mw56: Heap-based buffer overflow in Mozilla Thunderbird before 2
ghsa_unreviewed·2022-05-02
CVE-2008-4070 [HIGH] CWE-119 GHSA-47xq-mwq7-mw56: Heap-based buffer overflow in Mozilla Thunderbird before 2
Heap-based buffer overflow in Mozilla Thunderbird before 2.0.0.17 and SeaMonkey before 1.1.12 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long header in a news article, related to "canceling [a] newsgroup message" and "cancelled newsgroup messages."
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2008-10/msg00005.htmlhttp://secunia.com/advisories/32010http://secunia.com/advisories/32025http://secunia.com/advisories/32044http://secunia.com/advisories/32082http://secunia.com/advisories/32092http://secunia.com/advisories/32196http://secunia.com/advisories/33433http://secunia.com/advisories/33434http://secunia.com/advisories/34501http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.379422http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.412123http://sunsolve.sun.com/search/document.do?assetkey=1-26-256408-1http://www.debian.org/security/2009/dsa-1696http://www.debian.org/security/2009/dsa-1697http://www.mandriva.com/security/advisories?name=MDVSA-2008:206http://www.mozilla.org/security/announce/2008/mfsa2008-46.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0908.htmlhttp://www.securityfocus.com/bid/31411http://www.securitytracker.com/id?1020948http://www.ubuntu.com/usn/usn-647-1http://www.vupen.com/english/advisories/2009/0977https://bugzilla.mozilla.org/show_bug.cgi?id=425152https://exchange.xforce.ibmcloud.com/vulnerabilities/45426https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10933http://lists.opensuse.org/opensuse-security-announce/2008-10/msg00005.htmlhttp://secunia.com/advisories/32010http://secunia.com/advisories/32025http://secunia.com/advisories/32044http://secunia.com/advisories/32082http://secunia.com/advisories/32092http://secunia.com/advisories/32196http://secunia.com/advisories/33433http://secunia.com/advisories/33434http://secunia.com/advisories/34501http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.379422http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.412123http://sunsolve.sun.com/search/document.do?assetkey=1-26-256408-1http://www.debian.org/security/2009/dsa-1696http://www.debian.org/security/2009/dsa-1697http://www.mandriva.com/security/advisories?name=MDVSA-2008:206http://www.mozilla.org/security/announce/2008/mfsa2008-46.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0908.htmlhttp://www.securityfocus.com/bid/31411http://www.securitytracker.com/id?1020948http://www.ubuntu.com/usn/usn-647-1http://www.vupen.com/english/advisories/2009/0977https://bugzilla.mozilla.org/show_bug.cgi?id=425152https://exchange.xforce.ibmcloud.com/vulnerabilities/45426https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10933
2008-09-27
Published