CVE-2006-0295
Mozilla Firefox <1.5, Thunderbird <1.5 - RCE
Title source: llmDescription
Mozilla Firefox 1.5, Thunderbird 1.5 if Javascript is enabled in mail, and SeaMonkey before 1.0 might allow remote attackers to execute arbitrary code via the QueryInterface method of the built-in Location and Navigator objects, which leads to memory corruption.
Exploits (4)
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubyremotemultiple
https://www.exploit-db.com/exploits/16301
metasploit
WORKING POC
NORMAL
by hdm · rubypocosx
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/browser/firefox_queryinterface.rb
References (14)
Scores
EPSS
0.8341
EPSS Percentile
99.3%
Details
Status
published
Products (3)
mozilla/firefox
1.5
mozilla/seamonkey
1.0 (2 CPE variants)
mozilla/thunderbird
1.5
Published
Feb 02, 2006
Tracked Since
Feb 18, 2026