CVE-2006-2779
Mozilla Firefox and Thunderbird before 1.5.0.4 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) nested <option> tags in a select tag, (2) a DOMNodeRemoved mutation event, (3) "Content-implemented…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (6.96%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Mozilla Firefox and Thunderbird before 1.5.0.4 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) nested <option> tags in a select tag, (2) a DOMNodeRemoved mutation event, (3) "Content-implemented tree views," (4) BoxObjects, (5) the XBL implementation, (6) an iframe that attempts to remove itself, which leads to memory corruption.
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 6.96% probability · 94th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-94
- Affected
- mozilla/firefox · mozilla/thunderbird
- Source
- cve@mitre.org
References
- http://rhn.redhat.com/errata/RHSA-2006-0609.htmlVendor Advisory
- http://secunia.com/advisories/20376Patch, Vendor Advisory
- http://secunia.com/advisories/20382Patch, Vendor Advisory
- http://secunia.com/advisories/20561Patch, Vendor Advisory
- http://secunia.com/advisories/20709
- http://secunia.com/advisories/21134Vendor Advisory
- http://secunia.com/advisories/21176Vendor Advisory
- http://secunia.com/advisories/21178Vendor Advisory
- http://secunia.com/advisories/21183Vendor Advisory
- http://secunia.com/advisories/21188Vendor Advisory
- http://secunia.com/advisories/21210Vendor Advisory
- http://secunia.com/advisories/21269Vendor Advisory
- http://secunia.com/advisories/21270Vendor Advisory
- http://secunia.com/advisories/21324Vendor Advisory
- http://secunia.com/advisories/21336Vendor Advisory
- http://secunia.com/advisories/21532Vendor Advisory
- http://secunia.com/advisories/21607Vendor Advisory
- http://secunia.com/advisories/21631Vendor Advisory
- http://secunia.com/advisories/21634Vendor Advisory
- http://secunia.com/advisories/21654Vendor Advisory
- http://secunia.com/advisories/22065
- http://secunia.com/advisories/22066
- http://secunia.com/advisories/27216
- http://securitytracker.com/id?1016202Patch
- http://securitytracker.com/id?1016214Patch
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-102943-1
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-200387-1
- http://www.debian.org/security/2006/dsa-1118
- http://www.debian.org/security/2006/dsa-1120
- http://www.debian.org/security/2006/dsa-1134
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.