CVE-2010-0163
published 2010-03-23CVE-2010-0163: Mozilla Thunderbird before 2.0.0.24 and SeaMonkey before 1.1.19 process e-mail attachments with a parser that performs casts and line termination incorrectly…
PriorityP424medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
3.19%
86.6th percentile
Mozilla Thunderbird before 2.0.0.24 and SeaMonkey before 1.1.19 process e-mail attachments with a parser that performs casts and line termination incorrectly, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted message, related to message indexing.
Affected
87 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | seamonkey | <= 1.1.18 | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
vendor_redhat7.1HIGH
vendor_ubuntu6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: sctp: a race between ICMP protocol unreachable and connect()
vendor_redhat·2010-05-06·CVSS 7.1
CVE-2010-4526 [HIGH] CWE-662 kernel: sctp: a race between ICMP protocol unreachable and connect()
kernel: sctp: a race between ICMP protocol unreachable and connect()
Race condition in the sctp_icmp_proto_unreachable function in net/sctp/input.c in Linux kernel 2.6.11-rc2 through 2.6.33 allows remote attackers to cause a denial of service (panic) via an ICMP unreachable message to a socket that is already locked by a user, which causes the socket to be freed and triggers list corruption, related to the sctp_wait_for_connect function.
Statement: The Linux kernel as shipped with Red Hat Enterprise Linux 4 did not include
upstream commit history:5aabd1fe268e850c2e93048a5ccc5eb6970ac49c, and therefore
is not affected by this issue. This has been addressed in Red Hat Enterprise Linux 5, 6 and Red Hat Enterprise MRG via http://rhn.redhat.com/errata/RHSA-2011-0163.html, https://rhn.redhat.c
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2010-03-18·CVSS 6.8
CVE-2009-0689 [MEDIUM] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Thunderbird vulnerabilities
Several flaws were discovered in the JavaScript engine of Thunderbird. If a
user had JavaScript enabled and were tricked into viewing malicious web
content, a remote attacker could cause a denial of service or possibly
execute arbitrary code with the privileges of the user invoking the
program. (CVE-2009-0689, CVE-2009-2463, CVE-2009-3075)
Josh Soref discovered that the BinHex decoder used in Thunderbird contained
a flaw. If a user were tricked into viewing malicious content, a remote
attacker could cause a denial of service or possibly execute arbitrary code
with the privileges of the user invoking the program. (CVE-2009-3072)
It was discovered that Thunderbird did not properly manage memory when
using XUL tree el
Red Hat
seamonkey/thunderbird: crash when indexing certain messages with attachments
vendor_redhat·2010-03-16·CVSS 4.3
CVE-2010-0163 [MEDIUM] seamonkey/thunderbird: crash when indexing certain messages with attachments
seamonkey/thunderbird: crash when indexing certain messages with attachments
Mozilla Thunderbird before 2.0.0.24 and SeaMonkey before 1.1.19 process e-mail attachments with a parser that performs casts and line termination incorrectly, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted message, related to message indexing.
VulDB
Mozilla Thunderbird up to 1.5.0.10 memory corruption (Bug 505221 / Nessus ID 60809)
vuldb·2026-05-03·CVSS 4.3
CVE-2010-0163 [MEDIUM] Mozilla Thunderbird up to 1.5.0.10 memory corruption (Bug 505221 / Nessus ID 60809)
A vulnerability was found in Mozilla Thunderbird up to 1.5.0.10 and classified as critical. This affects an unknown function. Such manipulation leads to memory corruption.
This vulnerability is referenced as CVE-2010-0163. It is possible to launch the attack remotely. No exploit is available.
It is suggested to upgrade the affected component.
GHSA
GHSA-c9pm-wqw2-p2v7: Mozilla Thunderbird before 2
ghsa_unreviewed·2022-05-02
CVE-2010-0163 [MEDIUM] GHSA-c9pm-wqw2-p2v7: Mozilla Thunderbird before 2
Mozilla Thunderbird before 2.0.0.24 and SeaMonkey before 1.1.19 process e-mail attachments with a parser that performs casts and line termination incorrectly, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted message, related to message indexing.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2010-4644 Subversion: DoS (memory consumption) by processing blame or log -g requests on certain files
bugzilla·2011-01-06·CVSS 3.5
CVE-2010-4644 [LOW] CVE-2010-4644 Subversion: DoS (memory consumption) by processing blame or log -g requests on certain files
CVE-2010-4644 Subversion: DoS (memory consumption) by processing blame or log -g requests on certain files
A server-side memory leak in Subversion before v1.6.15
allowed remote attackers to cause a denial of service
(memory consumption and daemon outage or crash) via
Subversion client "blame" or "log" operations performed
on certain repository files, when the -g option (request
to display additional merge history for the file) was used.
References:
[1] http://svn.haxx.se/dev/archive-2010-11/0102.shtml
[2] http://svn.apache.org/repos/asf/subversion/tags/1.6.15/CHANGES
Upstream changeset:
[3] http://svn.apache.org/viewvc?view=revision&revision=1032808
Public PoC:
[4] http://svn.haxx.se/dev/archive-2010-11/0163.shtml
Discussion:
This issue did not affect the versions of the subversion p
Bugzilla
CVE-2010-0163 seamonkey/thunderbird: crash when indexing certain messages with attachments
bugzilla·2010-03-23·CVSS 4.3
CVE-2010-0163 [MEDIUM] CVE-2010-0163 seamonkey/thunderbird: crash when indexing certain messages with attachments
CVE-2010-0163 seamonkey/thunderbird: crash when indexing certain messages with attachments
Common Vulnerabilities and Exposures assigned an identifier CVE-2010-0163 to
the following vulnerability:
Name: CVE-2010-0163
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0163
Assigned: 20100106
Reference: CONFIRM: http://www.mozilla.org/security/announce/2010/mfsa2010-07.html
Reference: CONFIRM: https://bugzilla.mozilla.org/show_bug.cgi?id=505221
Reference: UBUNTU:USN-915-1
Reference: URL: http://www.ubuntu.com/usn/USN-915-1
Reference: BID:38831
Reference: URL: http://www.securityfocus.com/bid/38831
Reference: SECUNIA:39001
Reference: URL: http://secunia.com/advisories/39001
Reference: VUPEN:ADV-2010-0648
Reference: URL: http://www.vupen.com/english/advisories/2010/0648
Reference: X
http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.htmlhttp://secunia.com/advisories/38977http://secunia.com/advisories/39001http://www.mozilla.org/security/announce/2010/mfsa2010-07.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0499.htmlhttp://www.securityfocus.com/bid/38831http://www.ubuntu.com/usn/USN-915-1http://www.vupen.com/english/advisories/2010/0648http://www.vupen.com/english/advisories/2010/1556https://bugzilla.mozilla.org/show_bug.cgi?id=505221https://exchange.xforce.ibmcloud.com/vulnerabilities/56993https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10805https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14259http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.htmlhttp://secunia.com/advisories/38977http://secunia.com/advisories/39001http://www.mozilla.org/security/announce/2010/mfsa2010-07.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0499.htmlhttp://www.securityfocus.com/bid/38831http://www.ubuntu.com/usn/USN-915-1http://www.vupen.com/english/advisories/2010/0648http://www.vupen.com/english/advisories/2010/1556https://bugzilla.mozilla.org/show_bug.cgi?id=505221https://exchange.xforce.ibmcloud.com/vulnerabilities/56993https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10805https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14259
2010-03-23
Published