Integer overflow in the XSLT node sorting implementation in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, Thunderbird before 3.0.5, and SeaMonkey before 2.0.5 allows remote attackers to execute arbitrary code via a large text value for a node.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Firefox | Mozilla | 3.5 (including) | 3.5 (including) |
Firefox | Mozilla | 3.5.1 (including) | 3.5.1 (including) |
Firefox | Mozilla | 3.5.2 (including) | 3.5.2 (including) |
Firefox | Mozilla | 3.5.3 (including) | 3.5.3 (including) |
Firefox | Mozilla | 3.5.4 (including) | 3.5.4 (including) |
Firefox | Mozilla | 3.5.5 (including) | 3.5.5 (including) |
Firefox | Mozilla | 3.5.6 (including) | 3.5.6 (including) |
Firefox | Mozilla | 3.5.7 (including) | 3.5.7 (including) |
Firefox | Mozilla | 3.5.9 (including) | 3.5.9 (including) |
Red Hat Enterprise Linux 3 | RedHat | seamonkey-0:1.0.9-0.55.el3 | * |
Red Hat Enterprise Linux 4 | RedHat | seamonkey-0:1.0.9-58.el4_8 | * |
Red Hat Enterprise Linux 4 | RedHat | firefox-0:3.6.4-8.el4 | * |
Red Hat Enterprise Linux 4 | RedHat | thunderbird-0:1.5.0.12-28.el4 | * |
Red Hat Enterprise Linux 5 | RedHat | devhelp-0:0.12-21.el5 | * |
Red Hat Enterprise Linux 5 | RedHat | esc-0:1.1.0-12.el5 | * |
Red Hat Enterprise Linux 5 | RedHat | firefox-0:3.6.4-8.el5 | * |
Red Hat Enterprise Linux 5 | RedHat | gnome-python2-extras-0:2.14.2-7.el5 | * |
Red Hat Enterprise Linux 5 | RedHat | totem-0:2.16.7-7.el5 | * |
Red Hat Enterprise Linux 5 | RedHat | xulrunner-0:1.9.2.4-10.el5 | * |
Red Hat Enterprise Linux 5 | RedHat | yelp-0:2.16.0-26.el5 | * |
Red Hat Enterprise Linux 5 | RedHat | thunderbird-0:2.0.0.24-6.el5 | * |
Firefox | Ubuntu | dapper | * |
Firefox | Ubuntu | devel | * |
Firefox | Ubuntu | hardy | * |
Firefox | Ubuntu | lucid | * |
Firefox | Ubuntu | maverick | * |
Firefox | Ubuntu | natty | * |
Firefox | Ubuntu | oneiric | * |
Seamonkey | Ubuntu | devel | * |
Seamonkey | Ubuntu | hardy | * |
Seamonkey | Ubuntu | jaunty | * |
Seamonkey | Ubuntu | karmic | * |
Seamonkey | Ubuntu | lucid | * |
Seamonkey | Ubuntu | maverick | * |
Seamonkey | Ubuntu | natty | * |
Seamonkey | Ubuntu | oneiric | * |
Thunderbird | Ubuntu | devel | * |
Thunderbird | Ubuntu | lucid | * |
Thunderbird | Ubuntu | maverick | * |
Thunderbird | Ubuntu | natty | * |
Thunderbird | Ubuntu | oneiric | * |
Thunderbird | Ubuntu | upstream | * |
Xulrunner | Ubuntu | hardy | * |
Xulrunner | Ubuntu | jaunty | * |
Xulrunner | Ubuntu | karmic | * |
Xulrunner-1.9 | Ubuntu | hardy | * |
Xulrunner-1.9 | Ubuntu | jaunty | * |
Xulrunner-1.9.1 | Ubuntu | jaunty | * |
Xulrunner-1.9.1 | Ubuntu | karmic | * |
Xulrunner-1.9.2 | Ubuntu | hardy | * |
Xulrunner-1.9.2 | Ubuntu | jaunty | * |
Xulrunner-1.9.2 | Ubuntu | karmic | * |
Xulrunner-1.9.2 | Ubuntu | lucid | * |
Xulrunner-1.9.2 | Ubuntu | maverick | * |
Xulrunner-1.9.2 | Ubuntu | natty | * |