CVE-2006-0295

Mozilla Firefox 1.5, Thunderbird 1.5 if Javascript is enabled in mail, and SeaMonkey before 1.0 might allow remote attackers to execute arbitrary code via the QueryInterface method of the built-in Location and Navigator objects, which leads to memory corruption.
References
Link Resource
http://secunia.com/advisories/18700
http://secunia.com/advisories/18704
http://secunia.com/advisories/22065
http://securitytracker.com/id?1015570
http://www.kb.cert.org/vuls/id/759273 US Government Resource
http://www.mozilla.org/security/announce/2006/mfsa2006-04.html
http://www.securityfocus.com/archive/1/446657/100/200/threaded
http://www.securityfocus.com/archive/1/446657/100/200/threaded
http://www.securityfocus.com/bid/16476
http://www.us-cert.gov/cas/techalerts/TA06-038A.html US Government Resource
http://www.vupen.com/english/advisories/2006/0413
http://www.vupen.com/english/advisories/2006/3749
https://bugzilla.mozilla.org/show_bug.cgi?id=319296 Patch
https://exchange.xforce.ibmcloud.com/vulnerabilities/24433
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1562
http://secunia.com/advisories/18700
http://secunia.com/advisories/18704
http://secunia.com/advisories/22065
http://securitytracker.com/id?1015570
http://www.kb.cert.org/vuls/id/759273 US Government Resource
http://www.mozilla.org/security/announce/2006/mfsa2006-04.html
http://www.securityfocus.com/archive/1/446657/100/200/threaded
http://www.securityfocus.com/archive/1/446657/100/200/threaded
http://www.securityfocus.com/bid/16476
http://www.us-cert.gov/cas/techalerts/TA06-038A.html US Government Resource
http://www.vupen.com/english/advisories/2006/0413
http://www.vupen.com/english/advisories/2006/3749
https://bugzilla.mozilla.org/show_bug.cgi?id=319296 Patch
https://exchange.xforce.ibmcloud.com/vulnerabilities/24433
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1562
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mozilla:firefox:1.5:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:1.0:*:alpha:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:1.0:beta:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:1.5:*:*:*:*:*:*:*

History

21 Nov 2024, 00:06

Type Values Removed Values Added
References () http://secunia.com/advisories/18700 - () http://secunia.com/advisories/18700 -
References () http://secunia.com/advisories/18704 - () http://secunia.com/advisories/18704 -
References () http://secunia.com/advisories/22065 - () http://secunia.com/advisories/22065 -
References () http://securitytracker.com/id?1015570 - () http://securitytracker.com/id?1015570 -
References () http://www.kb.cert.org/vuls/id/759273 - US Government Resource () http://www.kb.cert.org/vuls/id/759273 - US Government Resource
References () http://www.mozilla.org/security/announce/2006/mfsa2006-04.html - () http://www.mozilla.org/security/announce/2006/mfsa2006-04.html -
References () http://www.securityfocus.com/archive/1/446657/100/200/threaded - () http://www.securityfocus.com/archive/1/446657/100/200/threaded -
References () http://www.securityfocus.com/bid/16476 - () http://www.securityfocus.com/bid/16476 -
References () http://www.us-cert.gov/cas/techalerts/TA06-038A.html - US Government Resource () http://www.us-cert.gov/cas/techalerts/TA06-038A.html - US Government Resource
References () http://www.vupen.com/english/advisories/2006/0413 - () http://www.vupen.com/english/advisories/2006/0413 -
References () http://www.vupen.com/english/advisories/2006/3749 - () http://www.vupen.com/english/advisories/2006/3749 -
References () https://bugzilla.mozilla.org/show_bug.cgi?id=319296 - Patch () https://bugzilla.mozilla.org/show_bug.cgi?id=319296 - Patch
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/24433 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/24433 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1562 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1562 -

Information

Published : 2006-02-02 20:06

Updated : 2024-11-21 00:06


NVD link : CVE-2006-0295

Mitre link : CVE-2006-0295

CVE.ORG link : CVE-2006-0295


JSON object : View

Products Affected

mozilla

  • firefox
  • thunderbird
  • seamonkey