9.3

CVE-2006-0749

nsHTMLContentSink.cpp in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors involving a "particular sequence of HTML tags" that leads to memory corruption.

Data is provided by the National Vulnerability Database (NVD)
MozillaFirefox Version >= 1.0 <= 1.5
MozillaMozilla Suite Version < 1.7.13
MozillaSeamonkey Version < 1.0
MozillaThunderbird Version >= 1.0 < 1.0.8
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 40.33% 0.97
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
http://www.vupen.com/english/advisories/2006/3391
Third Party Advisory
Permissions Required
http://www.securityfocus.com/bid/17516
Third Party Advisory
VDB Entry
http://www.vupen.com/english/advisories/2006/1356
Third Party Advisory
Permissions Required
http://www.kb.cert.org/vuls/id/736934
Third Party Advisory
US Government Resource
http://www.us-cert.gov/cas/techalerts/TA06-107A.html
Third Party Advisory
US Government Resource