CVE-2006-3803

Mozilla Firefox/Thunderbird/SeaMonkey Remote Code Execution via JavaScript Garbage Collection

Title source: llm
STIX 2.1

Description

Race condition in the JavaScript garbage collection in Mozilla Firefox 1.5 before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 might allow remote attackers to execute arbitrary code by causing the garbage collector to delete a temporary variable while it is still being used during the creation of a new Function object.

References (58)

Core 58
Core References
Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/19181
US Government Resource third-party-advisory x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA06-208A.html
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/441333/100/0/threaded
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/21216
Third Party Advisory vendor-advisory x_refsource_gentoo
http://www.gentoo.org/security/en/glsa/glsa-200608-03.xml
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1016588
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1016586
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/19873
Third Party Advisory, VDB Entry vendor-advisory x_refsource_hp
http://www.securityfocus.com/archive/1/446657/100/200/threaded
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/21229
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1016587
Vendor Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/329-1/
Vendor Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/327-1/
Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/usn-354-1
Vendor Advisory vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDKSA-2006:145
Vendor Advisory vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDKSA-2006:146
Vendor Advisory vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDKSA-2006:143
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/21243
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2006-0608.html
Third Party Advisory vendor-advisory x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-200608-02.xml
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/3748
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/22055
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/2998
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/21529
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2006-0594.html
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/21336
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/3749
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2006-0610.html
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2006-0609.html
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/22210
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/21607
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/21262
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/21532
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/21270
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/0083
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/21361
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/21631
Third Party Advisory, VDB Entry vendor-advisory x_refsource_hp
http://www.securityfocus.com/archive/1/446658/100/200/threaded
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/21275
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/21246
Vendor Advisory vendor-advisory x_refsource_suse
http://www.novell.com/linux/security/advisories/2006_48_seamonkey.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/27984
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2006-0611.html
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/21228
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/21250
Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/usn-350-1
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/21358
Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/265964
Issue Tracking x_refsource_confirm
https://issues.rpath.com/browse/RPL-536
Issue Tracking x_refsource_confirm
https://issues.rpath.com/browse/RPL-537
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/22066
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10635
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/21269
Third Party Advisory vendor-advisory x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-200608-04.xml
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/21343
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/22065
Vendor Advisory vendor-advisory x_refsource_sgi
ftp://patches.sgi.com/support/free/security/advisories/20060703-01-U.asc

Scores

EPSS 0.0438
EPSS Percentile 90.2%

Details

Status published
Products (11)
mozilla/firefox 1.5
mozilla/firefox 1.5.0.1
mozilla/firefox 1.5.0.2
mozilla/firefox 1.5.0.3
mozilla/firefox 1.5.0.4
mozilla/seamonkey 1.0 (2 CPE variants)
mozilla/seamonkey 1.0.1
mozilla/seamonkey 1.0.2
mozilla/thunderbird 1.5
mozilla/thunderbird 1.5.0.2
... and 1 more
Published Jul 27, 2006
Tracked Since Feb 18, 2026