CVE-2006-0295

Mozilla Firefox <1.5, Thunderbird <1.5 - RCE

Title source: llm

Description

Mozilla Firefox 1.5, Thunderbird 1.5 if Javascript is enabled in mail, and SeaMonkey before 1.0 might allow remote attackers to execute arbitrary code via the QueryInterface method of the built-in Location and Navigator objects, which leads to memory corruption.

Exploits (4)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotemultiple
https://www.exploit-db.com/exploits/16301
exploitdb WORKING POC VERIFIED
by H D Moore · remoteosx
https://www.exploit-db.com/exploits/1480
exploitdb WORKING POC VERIFIED
by H D Moore · remotelinux
https://www.exploit-db.com/exploits/1474
metasploit WORKING POC NORMAL
by hdm · rubypocosx
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/browser/firefox_queryinterface.rb

Scores

EPSS 0.8341
EPSS Percentile 99.3%

Details

Status published
Products (3)
mozilla/firefox 1.5
mozilla/seamonkey 1.0 (2 CPE variants)
mozilla/thunderbird 1.5
Published Feb 02, 2006
Tracked Since Feb 18, 2026