Use-after-free vulnerability in the nsContentUtils::ContentIsHostIncludingDescendantOf function in Mozilla Firefox before 25.0, Firefox ESR 24.x before 24.1, Thunderbird before 24.1, and SeaMonkey before 2.22 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via vectors involving HTML document templates.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Thunderbird | Mozilla | * | 24.0.1 (including) |
Thunderbird | Mozilla | 17.0 (including) | 17.0 (including) |
Thunderbird | Mozilla | 17.0.1 (including) | 17.0.1 (including) |
Thunderbird | Mozilla | 17.0.2 (including) | 17.0.2 (including) |
Thunderbird | Mozilla | 17.0.3 (including) | 17.0.3 (including) |
Thunderbird | Mozilla | 17.0.4 (including) | 17.0.4 (including) |
Thunderbird | Mozilla | 17.0.5 (including) | 17.0.5 (including) |
Thunderbird | Mozilla | 17.0.6 (including) | 17.0.6 (including) |
Thunderbird | Mozilla | 17.0.7 (including) | 17.0.7 (including) |
Thunderbird | Mozilla | 17.0.8 (including) | 17.0.8 (including) |
Thunderbird | Mozilla | 24.0 (including) | 24.0 (including) |
Thunderbird_esr | Mozilla | 17.0.9 (including) | 17.0.9 (including) |
Firefox | Ubuntu | devel | * |
Firefox | Ubuntu | lucid | * |
Firefox | Ubuntu | precise | * |
Firefox | Ubuntu | quantal | * |
Firefox | Ubuntu | raring | * |
Firefox | Ubuntu | saucy | * |
Firefox | Ubuntu | upstream | * |
Thunderbird | Ubuntu | devel | * |
Thunderbird | Ubuntu | lucid | * |
Thunderbird | Ubuntu | precise | * |
Thunderbird | Ubuntu | quantal | * |
Thunderbird | Ubuntu | raring | * |
Thunderbird | Ubuntu | saucy | * |
Thunderbird | Ubuntu | upstream | * |