CVE-2010-0163
Vulnerability Summary
Timeline
Description
Mozilla Thunderbird before 2.0.0.24 and SeaMonkey before 1.1.19 process e-mail attachments with a parser that performs casts and line termination incorrectly, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted message, related to message indexing.
CVSS Metrics
- v2.0•MEDIUM•Score: 4.3AV:N/AC:M/Au:N/C:N/I:N/A:P
EPSS Trends
Current EPSS score: 5.44%• Percentile: 90%
Affected Systems
- mozilla•seamonkey
≤ 1.1.18 | 1.0 | 1.0:alpha | 1.0:beta | 1.0.1 | 1.0.2 | 1.0.3 | 1.0.4 | 1.0.5 | 1.0.6 | 1.0.7 | 1.0.8 | 1.0.9 | 1.1 | 1.1:alpha | 1.1:beta | 1.1.1 | 1.1.2 | 1.1.3 | 1.1.4 | 1.1.5 | 1.1.6 | 1.1.7 | 1.1.8 | 1.1.9 | 1.1.10 | 1.1.11 | 1.1.12 | 1.1.13 | 1.1.14 | 1.1.15 | 1.1.16 | 1.1.17
- mozilla•thunderbird
≤ 2.0.0.23 | 0.1 | 0.2 | 0.3 | 0.4 | 0.5 | 0.6 | 0.7 | 0.7.1 | 0.7.2 | 0.7.3 | 0.8 | 0.9 | 1.0 | 1.0.1 | 1.0.2 | 1.0.3 | 1.0.4 | 1.0.5 | 1.0.6 | 1.0.7 | 1.0.8 | 1.5 | 1.5:beta2 | 1.5.0.1 | 1.5.0.2 | 1.5.0.3 | 1.5.0.4 | 1.5.0.5 | 1.5.0.6 | 1.5.0.7 | 1.5.0.8 | 1.5.0.9 | 1.5.0.10 | 1.5.0.11 | 1.5.0.12 | 1.5.0.13 | 1.5.0.14 | 1.5.1 | 1.5.2 | 2.0 | 2.0.0.0 | 2.0.0.1 | 2.0.0.2 | 2.0.0.3 | 2.0.0.4 | 2.0.0.5 | 2.0.0.6 | 2.0.0.7 | 2.0.0.8 | 2.0.0.9 | 2.0.0.12 | 2.0.0.14 | 2.0.0.16 | 2.0.0.17 | 2.0.0.18 | 2.0.0.19 | 2.0.0.21 | 2.0.0.22
References (13)
- http://secunia.com/advisories/39001
- http://www.vupen.com/english/advisories/2010/0648
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14259
- http://www.redhat.com/support/errata/RHSA-2010-0499.html
- https://bugzilla.mozilla.org/show_bug.cgi?id=505221
- http://www.vupen.com/english/advisories/2010/1556
- http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.html
- http://secunia.com/advisories/38977
- https://exchange.xforce.ibmcloud.com/vulnerabilities/56993
- http://www.securityfocus.com/bid/38831
- http://www.ubuntu.com/usn/USN-915-1
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10805
- http://www.mozilla.org/security/announce/2010/mfsa2010-07.html