[Forgot Password]
Login  Register Subscribe

23631

 
 

115038

 
 

96174

 
 

909

 
 

78077

 
 

109

Paid content will be excluded from the download.


Download | Alert*
CVE
view XML

CVE-2007-2867

Date: (C)2007-05-31   (M)2017-10-12
 
CVSS Score: 9.3Access Vector: NETWORK
Exploitability Subscore: 8.6Access Complexity: MEDIUM
Impact Subscore: 10.0Authentication: NONE
 Confidentiality: COMPLETE
 Integrity: COMPLETE
 Availability: COMPLETE











Multiple vulnerabilities in the layout engine for Mozilla Firefox 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, Thunderbird 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, and SeaMonkey 1.0.9 and 1.1.2 allow remote attackers to cause a denial of service (crash) via vectors related to dangling pointers, heap corruption, signed/unsigned, and other issues.

Reference:
SECTRACK-1018151
SECTRACK-1018153
SUNALERT-103136
http://www.securityfocus.com/archive/1/archive/1/470172/100/200/threaded
http://www.securityfocus.com/archive/1/archive/1/471842/100/0/threaded
SUNALERT-201532
BID-24242
SECUNIA-24406
SECUNIA-24456
SECUNIA-25469
SECUNIA-25476
SECUNIA-25488
SECUNIA-25489
SECUNIA-25490
SECUNIA-25491
SECUNIA-25492
SECUNIA-25496
SECUNIA-25533
SECUNIA-25534
SECUNIA-25559
SECUNIA-25635
SECUNIA-25644
SECUNIA-25647
SECUNIA-25664
SECUNIA-25685
SECUNIA-25750
SECUNIA-25858
SECUNIA-27423
SECUNIA-28363
OSVDB-35134
ADV-2007-1994
ADV-2007-3664
ADV-2008-0082
DSA-1300
DSA-1305
DSA-1306
DSA-1308
FEDORA-2007-308
FEDORA-2007-309
GLSA-200706-06
HPSBUX02153
MDKSA-2007:119
MDKSA-2007:120
MDKSA-2007:126
MDKSA-2007:131
RHSA-2007:0400
RHSA-2007:0401
RHSA-2007:0402
SSA:2007-066-04
SSA:2007-152-02
SSRT061181
SSRT061236
SUSE-SA:2007:036
TA07-151A
USN-468-1
USN-469-1
VU#751636
http://www.mozilla.org/security/announce/2007/mfsa2007-12.html
https://issues.rpath.com/browse/RPL-1424
mozilla-layoutengine-dos(34604)

CPE    45
cpe:/a:mozilla:thunderbird:1.5.2
cpe:/a:mozilla:thunderbird:1.5.1
cpe:/a:mozilla:thunderbird:1.5.0.8
cpe:/a:mozilla:thunderbird:1.5.0.7
...
CWE    1
CWE-119

© 2013 SecPod Technologies