[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248149

 
 

909

 
 

194803

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2006-0749Date: (C)2006-04-14   (M)2024-03-27


nsHTMLContentSink.cpp in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors involving a "particular sequence of HTML tags" that leads to memory corruption.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 9.3
Exploit Score: 8.6
Impact Score: 10.0
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: COMPLETE
Integrity: COMPLETE
Availability: COMPLETE
  
Reference:
SUNALERT-102550
BID-17516
SECUNIA-19631
SECUNIA-19696
SECUNIA-19714
SECUNIA-19721
SECUNIA-19729
SECUNIA-19746
SECUNIA-19759
SECUNIA-19780
SECUNIA-19794
SECUNIA-19811
SECUNIA-19821
SECUNIA-19823
SECUNIA-19852
SECUNIA-19862
SECUNIA-19863
SECUNIA-19902
SECUNIA-19941
SECUNIA-19950
SECUNIA-20051
20060404-01-U
http://www.securityfocus.com/archive/1/431126/100/0/threaded
SECUNIA-21033
SECUNIA-21622
SUNALERT-228526
SREASON-729
ADV-2006-1356
ADV-2006-3391
DSA-1044
DSA-1046
DSA-1051
FEDORA-2006-410
FEDORA-2006-411
FLSA:189137-1
FLSA:189137-2
GLSA-200604-12
GLSA-200604-18
GLSA-200605-09
HPSBUX02122
MDKSA-2006:075
MDKSA-2006:076
MDKSA-2006:078
RHSA-2006:0328
RHSA-2006:0329
RHSA-2006:0330
SCOSA-2006.26
SSRT061145
SUSE-SA:2006:021
SUSE-SA:2006:022
TA06-107A
USN-271-1
USN-275-1
USN-276-1
VU#736934
http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm
http://www.mozilla.org/security/announce/2006/mfsa2006-18.html
http://www.zerodayinitiative.com/advisories/ZDI-06-009.html
mozilla-nshtmlcontentsink-memory-corruption(25819)
oval:org.mitre.oval:def:11704
oval:org.mitre.oval:def:1848

CPE    4
cpe:/a:mozilla:thunderbird
cpe:/a:mozilla:seamonkey
cpe:/a:mozilla:firefox
cpe:/a:mozilla:mozilla_suite
...
CWE    1
CWE-399
OVAL    1
oval:org.mitre.oval:def:1848

© SecPod Technologies