CVE-2006-3806
Multiple integer overflows in the Javascript engine in Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 might allow remote attackers to execute arbitrary code via vectors involving (1) long strings in the toSource…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (5.46%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple integer overflows in the Javascript engine in Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 might allow remote attackers to execute arbitrary code via vectors involving (1) long strings in the toSource method of the Object, Array, and String objects; and (2) unspecified "string function arguments."
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 5.46% probability · 92th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-189
- Affected
- mozilla/firefox · mozilla/seamonkey · mozilla/thunderbird
- Source
- secalert@redhat.com
References
- ftp://patches.sgi.com/support/free/security/advisories/20060703-01-U.asc
- http://rhn.redhat.com/errata/RHSA-2006-0609.htmlVendor Advisory
- http://secunia.com/advisories/19873Patch, Vendor Advisory
- http://secunia.com/advisories/21216Patch, Vendor Advisory
- http://secunia.com/advisories/21228Patch, Vendor Advisory
- http://secunia.com/advisories/21229Patch, Vendor Advisory
- http://secunia.com/advisories/21243Vendor Advisory
- http://secunia.com/advisories/21246Vendor Advisory
- http://secunia.com/advisories/21250Vendor Advisory
- http://secunia.com/advisories/21262Vendor Advisory
- http://secunia.com/advisories/21269Vendor Advisory
- http://secunia.com/advisories/21270Vendor Advisory
- http://secunia.com/advisories/21275Vendor Advisory
- http://secunia.com/advisories/21336Vendor Advisory
- http://secunia.com/advisories/21343Vendor Advisory
- http://secunia.com/advisories/21358Vendor Advisory
- http://secunia.com/advisories/21361Vendor Advisory
- http://secunia.com/advisories/21529Vendor Advisory
- http://secunia.com/advisories/21532Vendor Advisory
- http://secunia.com/advisories/21607Vendor Advisory
- http://secunia.com/advisories/21631Vendor Advisory
- http://secunia.com/advisories/21634Vendor Advisory
- http://secunia.com/advisories/21654Vendor Advisory
- http://secunia.com/advisories/21675Vendor Advisory
- http://secunia.com/advisories/22055
- http://secunia.com/advisories/22065
- http://secunia.com/advisories/22066
- http://secunia.com/advisories/22210
- http://secunia.com/advisories/22342
- http://security.gentoo.org/glsa/glsa-200608-02.xml
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.