CVE-2006-3113
Mozilla Firefox 1.5 before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via simultaneous XPCOM events, which causes a timer object to be…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (6.42%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Mozilla Firefox 1.5 before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via simultaneous XPCOM events, which causes a timer object to be deleted in a way that triggers memory corruption.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 6.42% probability · 93th percentile
- CISA KEV
- Not listed
- Affected
- mozilla/firefox · mozilla/seamonkey · mozilla/thunderbird
- Source
- PSIRT-CNA@flexerasoftware.com
References
- ftp://patches.sgi.com/support/free/security/advisories/20060703-01-U.asc
- http://rhn.redhat.com/errata/RHSA-2006-0609.html
- http://secunia.com/advisories/19873Patch, Vendor Advisory
- http://secunia.com/advisories/21216Patch, Vendor Advisory
- http://secunia.com/advisories/21228Patch, Vendor Advisory
- http://secunia.com/advisories/21229Patch, Vendor Advisory
- http://secunia.com/advisories/21243
- http://secunia.com/advisories/21246
- http://secunia.com/advisories/21250
- http://secunia.com/advisories/21262
- http://secunia.com/advisories/21269
- http://secunia.com/advisories/21270
- http://secunia.com/advisories/21275
- http://secunia.com/advisories/21336
- http://secunia.com/advisories/21343
- http://secunia.com/advisories/21358
- http://secunia.com/advisories/21361
- http://secunia.com/advisories/21529
- http://secunia.com/advisories/21532
- http://secunia.com/advisories/21607
- http://secunia.com/advisories/21631
- http://secunia.com/advisories/22055
- http://secunia.com/advisories/22065
- http://secunia.com/advisories/22066
- http://secunia.com/advisories/22210
- http://secunia.com/secunia_research/2006-53/advisory/Vendor Advisory
- http://security.gentoo.org/glsa/glsa-200608-02.xml
- http://security.gentoo.org/glsa/glsa-200608-04.xml
- http://securitytracker.com/id?1016586
- http://securitytracker.com/id?1016587
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.