CVE-2006-3677
Mozilla Firefox 1.5 before 1.5.0.5 and SeaMonkey before 1.0.3 allows remote attackers to execute arbitrary code by changing certain properties of the window navigator object (window.navigator) that are accessed when Java starts up, which causes a crash…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 78.7%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
Mozilla Firefox 1.5 before 1.5.0.5 and SeaMonkey before 1.0.3 allows remote attackers to execute arbitrary code by changing certain properties of the window navigator object (window.navigator) that are accessed when Java starts up, which causes a crash that leads to code execution.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 78.69% probability · 100th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-16
- Affected
- mozilla/firefox · mozilla/seamonkey
- Source
- cve@mitre.org
References
- ftp://patches.sgi.com/support/free/security/advisories/20060703-01-U.asc
- http://rhn.redhat.com/errata/RHSA-2006-0609.htmlVendor Advisory
- http://secunia.com/advisories/19873Patch, Vendor Advisory
- http://secunia.com/advisories/21216Patch, Vendor Advisory
- http://secunia.com/advisories/21229Patch, Vendor Advisory
- http://secunia.com/advisories/21243Vendor Advisory
- http://secunia.com/advisories/21246Vendor Advisory
- http://secunia.com/advisories/21262Vendor Advisory
- http://secunia.com/advisories/21269Vendor Advisory
- http://secunia.com/advisories/21270Vendor Advisory
- http://secunia.com/advisories/21336Vendor Advisory
- http://secunia.com/advisories/21343Vendor Advisory
- http://secunia.com/advisories/21361Vendor Advisory
- http://secunia.com/advisories/21529Vendor Advisory
- http://secunia.com/advisories/21532Vendor Advisory
- http://secunia.com/advisories/21631Vendor Advisory
- http://secunia.com/advisories/22066Vendor Advisory
- http://secunia.com/advisories/22210Vendor Advisory
- http://security.gentoo.org/glsa/glsa-200608-02.xml
- http://securitytracker.com/id?1016586
- http://securitytracker.com/id?1016587
- http://www.gentoo.org/security/en/glsa/glsa-200608-03.xml
- http://www.kb.cert.org/vuls/id/670060Third Party Advisory, US Government Resource
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:143
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:145
- http://www.mozilla.org/security/announce/2006/mfsa2006-45.htmlVendor Advisory
- http://www.novell.com/linux/security/advisories/2006_48_seamonkey.html
- http://www.redhat.com/support/errata/RHSA-2006-0594.htmlVendor Advisory
- http://www.redhat.com/support/errata/RHSA-2006-0608.htmlVendor Advisory
- http://www.redhat.com/support/errata/RHSA-2006-0610.htmlVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.