CVE-2006-1993

Mozilla Firefox - Resource Management Error

Title source: rule

Description

Mozilla Firefox 1.5.0.2, when designMode is enabled, allows remote attackers to cause a denial of service and possibly execute arbitrary code via certain Javascript that is not properly handled by the contentWindow.focus method in an iframe, which causes a reference to a deleted controller context object. NOTE: this was originally claimed to be a buffer overflow in (1) js320.dll and (2) xpcom_core.dll, but the vendor disputes this claim.

Exploits (1)

exploitdb WORKING POC VERIFIED
by splices · htmldosmultiple
https://www.exploit-db.com/exploits/1716

Scores

EPSS 0.5732
EPSS Percentile 98.2%

Details

CWE
CWE-399
Status published
Products (1)
mozilla/firefox 1.5.0.2
Published Apr 25, 2006
Tracked Since Feb 18, 2026