CVE-2009-2210
published 2009-06-25CVE-2009-2210: Mozilla Thunderbird before 2.0.0.22 and SeaMonkey before 1.1.17 allow remote attackers to cause a denial of service (application crash) or possibly execute…
PriorityP433critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
3.80%
88.8th percentile
Mozilla Thunderbird before 2.0.0.22 and SeaMonkey before 1.1.17 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a multipart/alternative e-mail message containing a text/enhanced part that triggers access to an incorrect object type.
Affected
100 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | seamonkey | <= 1.1.16 | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xmgw-g27r-xxpm: Mozilla Thunderbird before 2
ghsa_unreviewed·2022-05-02
CVE-2009-2210 [HIGH] GHSA-xmgw-g27r-xxpm: Mozilla Thunderbird before 2
Mozilla Thunderbird before 2.0.0.22 and SeaMonkey before 1.1.17 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a multipart/alternative e-mail message containing a text/enhanced part that triggers access to an incorrect object type.
Red Hat
Thunderbird mail crash
vendor_redhat·2009-06-22·CVSS 9.3
CVE-2009-2210 [CRITICAL] Thunderbird mail crash
Thunderbird mail crash
Mozilla Thunderbird before 2.0.0.22 and SeaMonkey before 1.1.17 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a multipart/alternative e-mail message containing a text/enhanced part that triggers access to an incorrect object type.
No detection rules found.
No public exploits indexed.
http://secunia.com/advisories/35561http://secunia.com/advisories/35602http://secunia.com/advisories/35633http://secunia.com/advisories/35882http://securitytracker.com/id?1022433http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.425408http://www.debian.org/security/2009/dsa-1830http://www.mandriva.com/security/advisories?name=MDVSA-2009:141http://www.mozilla.org/security/announce/2009/mfsa2009-33.htmlhttp://www.redhat.com/support/errata/RHSA-2009-1134.htmlhttp://www.securityfocus.com/bid/35461http://www.slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.454275https://bugzilla.mozilla.org/show_bug.cgi?id=495057https://exchange.xforce.ibmcloud.com/vulnerabilities/51315https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9994https://www.redhat.com/archives/fedora-package-announce/2009-July/msg00444.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-July/msg00504.htmlhttp://secunia.com/advisories/35561http://secunia.com/advisories/35602http://secunia.com/advisories/35633http://secunia.com/advisories/35882http://securitytracker.com/id?1022433http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.425408http://www.debian.org/security/2009/dsa-1830http://www.mandriva.com/security/advisories?name=MDVSA-2009:141http://www.mozilla.org/security/announce/2009/mfsa2009-33.htmlhttp://www.redhat.com/support/errata/RHSA-2009-1134.htmlhttp://www.securityfocus.com/bid/35461http://www.slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.454275https://bugzilla.mozilla.org/show_bug.cgi?id=495057https://exchange.xforce.ibmcloud.com/vulnerabilities/51315https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9994https://www.redhat.com/archives/fedora-package-announce/2009-July/msg00444.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-July/msg00504.html
2009-06-25
Published