CVE-2008-4070
Heap-based buffer overflow in Mozilla Thunderbird before 2.0.0.17 and SeaMonkey before 1.1.12 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long header in a news article, related to "canceling [a] newsgroup message" and "cancelled newsgroup messages."
- Affected products
- Thunderbird, Red Hat, Seamonkey, Suse
- Mozilla Seamonkey
- ≤ 1.1.11, 1.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, 1.0.5, 1.0.6, 1.0.7, 1.0.8, 1.0.9, 1.0.99, 1.1, 1.1.1, 1.1.2, 1.1.10
- Mozilla Thunderbird
- ≤ 2.0.0.16, 0.1, 0.2, 0.3, 0.4, 0.5, 0.6, 0.7, 0.7.1, 0.7.2, 0.7.3, 0.8, 0.9, 1.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, 1.0.5, 1.0.6, 1.0.7, 1.0.8, 1.5, 1.5.0.1
- Fix
- Available
- CVSS 2.0
- 10.0 HIGH
- EPSS
- 7.4% (94th percentile)
- Weakness
- CWE-119
- NVD status
- Modified
- Published
- 2008-09-27
CVE-2008-4070 at NVD
No indexed exploits for CVE-2008-4070 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2008-4070 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.