Free and open-source vulnerability scanner

Mageni eases for you the vulnerability scanning, assessment, and management process. It is free and open-source.

Install Now

Available for macOS, Windows, and Linux

App screenshot

Mozilla Thunderbird Multiple Vulnerabilities-01 Mar14 (Mac OS X)

Information

Severity

Severity

Critical

Family

Family

General

CVSSv2 Base

CVSSv2 Base

9.3

CVSSv2 Vector

CVSSv2 Vector

AV:N/AC:M/Au:N/C:C/I:C/A:C

Solution Type

Solution Type

Vendor Patch

Created

Created

10 years ago

Modified

Modified

5 years ago

Summary

This host is installed with Mozilla Thunderbird and is prone to multiple vulnerabilities.

Insight

Insight

Multiple flaws are due to, - Local users can gain privileges by modifying the extracted Mar contents during an update. - A boundary error when decoding WAV audio files. - An error when performing polygon rendering in MathML. - The session-restore feature does not consider the Content Security Policy of a data URL. - A timing error when processing SVG format images with filters and displacements. - A use-after-free error when handling garbage collection of TypeObjects under memory pressure. - An error within the TypedArrayObject implementation when handling neutered ArrayBuffer objects. - And some unspecified errors exist.

Affected Software

Affected Software

Mozilla Thunderbird version before 24.4 on Mac OS X

Detection Method

Detection Method

Checks if a vulnerable version is present on the target host.

Solution

Solution

Upgrade to Mozilla Thunderbird version 24.4 or later.