First published: Wed Apr 22 2009(Updated: )
The browser engine in Mozilla Firefox before 3.0.9, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.16 allows remote attackers to cause a denial of service (application crash) and possibly trigger memory corruption via vectors related to nsSVGElement::BindToTree.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla SeaMonkey | =1.1.10 | |
Firefox | =0.1 | |
Thunderbird | =1.5.0.7 | |
Firefox | =0.9_rc | |
Thunderbird | =0.6 | |
Mozilla SeaMonkey | =1.0.3 | |
Firefox | =0.8 | |
Firefox | =2.0.0.12 | |
Thunderbird | =0.7.2 | |
Firefox | =1.5-beta2 | |
Thunderbird | =2.0.0.4 | |
Mozilla SeaMonkey | =1.1.8 | |
Firefox | =3.0.7 | |
Firefox | =1.5.2 | |
Thunderbird | <=2.0.0.21 | |
Mozilla SeaMonkey | =1.0.1 | |
Mozilla SeaMonkey | =1.1.7 | |
Mozilla SeaMonkey | =1.5.0.10 | |
Thunderbird | =2.0.0.6 | |
Mozilla SeaMonkey | =1.0.6 | |
Firefox | =1.5.0.6 | |
Firefox | =1.8 | |
Mozilla SeaMonkey | =1.0.9 | |
Thunderbird | =0.3 | |
Mozilla SeaMonkey | =1.1.3 | |
Firefox | =2.0.0.2 | |
Firefox | =1.5.0.10 | |
Firefox | =1.5.0.3 | |
Thunderbird | =0.2 | |
Mozilla SeaMonkey | =1.0 | |
Thunderbird | =2.0_.5 | |
Thunderbird | =1.0.7 | |
Firefox | =1.5.0.11 | |
Thunderbird | =2.0.0.18 | |
Mozilla SeaMonkey | =1.0.99 | |
Thunderbird | =2.0.0.9 | |
Firefox | =1.5.4 | |
Mozilla SeaMonkey | =1.1.5 | |
Mozilla SeaMonkey | =1.0.7 | |
Firefox | =1.0.2 | |
Mozilla SeaMonkey | =1.0-beta | |
Thunderbird | =2.0_.12 | |
Thunderbird | =2.0.0.15 | |
Firefox | =3.0.4 | |
Firefox | =1.5-beta1 | |
Mozilla SeaMonkey | =1.1-alpha | |
Thunderbird | =2.0.0.16 | |
Thunderbird | =2.0.0.20 | |
Thunderbird | =2.0.0.8 | |
Thunderbird | =2.0.0.7 | |
Firefox | =3.0.5 | |
Mozilla SeaMonkey | =1.0-alpha | |
Thunderbird | =1.7.1 | |
Thunderbird | =2.0_8 | |
Firefox | =1.5 | |
Thunderbird | =1.5.0.3 | |
Firefox | =0.9.1 | |
Thunderbird | =1.5.0.10 | |
Thunderbird | =1.5.0.5 | |
Firefox | =1.0.4 | |
Firefox | =2.0.0.7 | |
Firefox | =1.0.7 | |
Thunderbird | =1.5.0.6 | |
Mozilla SeaMonkey | =1.1.12 | |
Mozilla SeaMonkey | =1.1 | |
Firefox | =2.0.0.9 | |
Firefox | =0.10.1 | |
Thunderbird | =1.0 | |
Thunderbird | =2.0.0.3 | |
Firefox | =0.9 | |
Thunderbird | =1.0.1 | |
Firefox | =2.0.0.16 | |
Mozilla SeaMonkey | =1.1.14 | |
Thunderbird | =1.5-beta2 | |
Firefox | =3.0-beta2 | |
Firefox | =1.5.6 | |
Thunderbird | =2.0.0.2 | |
Firefox | =2.0.0.17 | |
Firefox | =0.7 | |
Mozilla SeaMonkey | =1.1.2 | |
Firefox | =2.0.0.15 | |
Firefox | =0.2 | |
Mozilla SeaMonkey | =1.0.2 | |
Mozilla SeaMonkey | =1.0.8 | |
Thunderbird | =1.0.2 | |
Firefox | =0.3 | |
Thunderbird | =2.0.0.0 | |
Thunderbird | =1.5.0.13 | |
Mozilla SeaMonkey | =1.1.11 | |
Firefox | =1.0 | |
Mozilla SeaMonkey | =1.5.0.9 | |
Firefox | =3.0.3 | |
Mozilla SeaMonkey | =1.1-beta | |
Mozilla SeaMonkey | =1.1.1 | |
Firefox | =1.5.0.7 | |
Thunderbird | =2.0.0.12 | |
Firefox | =2.0 | |
Thunderbird | =1.5 | |
Firefox | =1.0.1 | |
Mozilla SeaMonkey | =1.5.0.8 | |
Thunderbird | =1.5.0.2 | |
Mozilla SeaMonkey | =1.1.5-1.1.10 | |
Firefox | =2.0-beta1 | |
Firefox | =2.0.0.14 | |
Firefox | =0.6 | |
Thunderbird | =2.0.0.13 | |
Mozilla SeaMonkey | =1.0.5 | |
Firefox | =0.7.1 | |
Thunderbird | =2.0_.9 | |
Firefox | =3.0.6 | |
Thunderbird | =1.5.0.8 | |
Thunderbird | =2.0.0.14 | |
Firefox | =1.5.0.8 | |
Firefox | =1.0.6 | |
Thunderbird | =0.5 | |
Thunderbird | =1.0.4 | |
Firefox | =2.0.0.3 | |
Thunderbird | =1.5.2 | |
Firefox | =1.5.0.9 | |
Thunderbird | =2.0.0.17 | |
Firefox | =1.5.0.5 | |
Firefox | =1.5.7 | |
Firefox | =1.5.0.12 | |
Thunderbird | =1.5.0.9 | |
Thunderbird | =1.5.0.11 | |
Thunderbird | =0.9 | |
Thunderbird | =1.0.3 | |
Firefox | =2.0.0.6 | |
Mozilla SeaMonkey | =1.1.6 | |
Thunderbird | =2.0.0.11 | |
Thunderbird | =1.5.0.12 | |
Thunderbird | =2.0_.13 | |
Firefox | =3.0 | |
Firefox | =2.0.0.11 | |
Firefox | =1.5.0.2 | |
Firefox | =1.0.3 | |
Firefox | =3.0.1 | |
Firefox | =2.0.0.4 | |
Firefox | =0.5 | |
Firefox | =0.6.1 | |
Firefox | =1.5.1 | |
Thunderbird | =2.0_.14 | |
Thunderbird | =0.7.3 | |
Firefox | =2.0.0.21 | |
Firefox | =0.9.3 | |
Firefox | =2.0.0.13 | |
Firefox | =2.0.0.18 | |
Thunderbird | =0.4 | |
Mozilla SeaMonkey | =1.0 | |
Thunderbird | =1.5.1 | |
Thunderbird | =0.7 | |
Thunderbird | =1.5.0.14 | |
Firefox | =2.0-rc2 | |
Firefox | =2.0.0.1 | |
Thunderbird | =1.0.6 | |
Firefox | =3.0.2 | |
Thunderbird | =1.0.5-beta | |
Thunderbird | =2.0.0.5 | |
Thunderbird | =1.7.3 | |
Mozilla SeaMonkey | =1.0.4 | |
Firefox | =1.5.5 | |
Firefox | =0.9.2 | |
Firefox | =1.0-preview_release | |
Thunderbird | =2.0.0.1 | |
Firefox | =2.0-beta_1 | |
Mozilla SeaMonkey | =1.1.9 | |
Mozilla SeaMonkey | =1.1.13 | |
Firefox | =2.0.0.20 | |
Mozilla SeaMonkey | <=1.1.15 | |
Thunderbird | =1.5.0.1 | |
Firefox | =2.0.0.8 | |
Thunderbird | =2.0_.4 | |
Thunderbird | =1.0.8 | |
Firefox | <=3.0.8 | |
Thunderbird | =0.1 | |
Firefox | =3.0-beta5 | |
Firefox | =0.9-rc | |
Firefox | =2.0.0.19 | |
Firefox | =1.5.8 | |
Firefox | =1.5.3 | |
Firefox | =0.4 | |
Thunderbird | =0.7.1 | |
Thunderbird | =1.0.5 | |
Thunderbird | =0.8 | |
Firefox | =1.5.0.4 | |
Firefox | =1.5.0.1 | |
Firefox | =0.10 | |
Thunderbird | =2.0_.6 | |
Firefox | =1.0.5 | |
Firefox | =2.0.0.5 | |
Firefox | =2.0.0.10 | |
Firefox | =2.0-rc3 | |
Firefox | =3.0-alpha | |
Thunderbird | =2.0.0.19 | |
Firefox | =1.0.6 | |
Thunderbird | =1.5.0.4 | |
Mozilla SeaMonkey | =1.1.4 | |
Firefox | =1.0.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-1303 has a CVSS score indicating it can lead to a denial of service and potentially memory corruption.
To fix CVE-2009-1303, update Mozilla Firefox to version 3.0.9 or later, Thunderbird to version 2.0.0.22 or later, or SeaMonkey to version 1.1.16 or later.
CVE-2009-1303 affects versions of Mozilla Firefox before 3.0.9, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.16.
CVE-2009-1303 is a vulnerability that allows remote attackers to cause denial of service and may trigger memory corruption in affected software.
Check your version of Mozilla Firefox, Thunderbird, or SeaMonkey against the affected versions listed for CVE-2009-1303.