5.1

CVE-2006-0295

Mozilla Firefox 1.5, Thunderbird 1.5 if Javascript is enabled in mail, and SeaMonkey before 1.0 might allow remote attackers to execute arbitrary code via the QueryInterface method of the built-in Location and Navigator objects, which leads to memory corruption.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mozilla ≫ Firefox Version 1.5
Mozilla ≫ Seamonkey Version 1.0 Edition alpha
Mozilla ≫ Seamonkey Version 1.0 Update beta
Mozilla ≫ Thunderbird Version 1.5
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 71.31% 0.993
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.1 4.9 6.4
AV:N/AC:H/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/18700
http://secunia.com/advisories/18704
http://www.securityfocus.com/bid/16476
http://www.vupen.com/english/advisories/2006/0413
http://secunia.com/advisories/22065
http://securitytracker.com/id?1015570
http://www.securityfocus.com/archive/1/446657/100/200/threaded
http://www.vupen.com/english/advisories/2006/3749
http://www.kb.cert.org/vuls/id/759273
US Government Resource
http://www.mozilla.org/security/announce/2006/mfsa2006-04.html
http://www.us-cert.gov/cas/techalerts/TA06-038A.html
US Government Resource
https://bugzilla.mozilla.org/show_bug.cgi?id=319296
Patch
https://exchange.xforce.ibmcloud.com/vulnerabilities/24433
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1562