CVE-2006-3731

Mozilla Firefox 1.5.0.4 - Denial of Service via Multipart Form Data Handling

Title source: llm
STIX 2.1

Description

Mozilla Firefox 1.5.0.4 and earlier allows remote user-assisted attackers to cause a denial of service (crash) via a form with a multipart/form-data encoding and a user-uploaded file. NOTE: a third party has claimed that this issue might be related to the LiveHTTPHeaders extension.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/440119/100/100/threaded
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/440506/100/0/threaded

Scores

EPSS 0.0095
EPSS Percentile 57.2%

Details

Status published
Products (5)
mozilla/firefox 1.5 (3 CPE variants)
mozilla/firefox 1.5.0.1
mozilla/firefox 1.5.0.2
mozilla/firefox 1.5.0.3
mozilla/firefox 1.5.0.4
Published Jul 21, 2006
Tracked Since Feb 18, 2026