5.1

CVE-2006-0297

Multiple integer overflows in Mozilla Firefox 1.5, Thunderbird 1.5 if Javascript is enabled in mail, and SeaMonkey before 1.0 might allow remote attackers to execute arbitrary code via the (1) EscapeAttributeValue in jsxml.c for E4X, (2) nsSVGCairoSurface::Init in SVG, and (3) nsCanvasRenderingContext2D.cpp in Canvas.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mozilla ≫ Firefox Version 1.5
Mozilla ≫ Firefox Version 1.5 Update beta1
Mozilla ≫ Seamonkey Version 1.0 Edition alpha
Mozilla ≫ Seamonkey Version 1.0 Update beta
Mozilla ≫ Thunderbird Version 1.5
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.94% 0.893
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.1 4.9 6.4
AV:N/AC:H/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/18700
http://secunia.com/advisories/18704
http://www.securityfocus.com/bid/16476
http://www.vupen.com/english/advisories/2006/0413
http://secunia.com/advisories/22065
http://securitytracker.com/id?1015570
http://www.securityfocus.com/archive/1/446657/100/200/threaded
http://www.vupen.com/english/advisories/2006/3749
http://www.mozilla.org/security/announce/2006/mfsa2006-06.html
https://bugzilla.mozilla.org/show_bug.cgi?id=319872
https://bugzilla.mozilla.org/show_bug.cgi?id=322215
https://exchange.xforce.ibmcloud.com/vulnerabilities/24435
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1339