9.3

CVE-2006-6504

Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to execute arbitrary code by appending an SVG comment DOM node to another type of document, which triggers memory corruption.

Data is provided by the National Vulnerability Database (NVD)
MozillaFirefox Version >= 1.5 < 1.5.0.9
MozillaFirefox Version >= 2.0 < 2.0.0.1
MozillaSeamonkey Version < 1.0.7
CanonicalUbuntu Linux Version5.10
CanonicalUbuntu Linux Version6.06 SwEditionlts
CanonicalUbuntu Linux Version6.10
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 41.55% 0.973
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
CWE-94 Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

http://www.securityfocus.com/bid/21668
Third Party Advisory
VDB Entry
http://www.us-cert.gov/cas/techalerts/TA06-354A.html
Third Party Advisory
US Government Resource
http://securitytracker.com/id?1017417
Third Party Advisory
VDB Entry
http://securitytracker.com/id?1017418
Third Party Advisory
VDB Entry
http://www.kb.cert.org/vuls/id/928956
Third Party Advisory
US Government Resource