CVE-2006-3806
Mozilla Firefox, Thunderbird, and SeaMonkey - Remote Code Execution via Integer Overflow in JavaScript Engine
Title source: llmDescription
Multiple integer overflows in the Javascript engine in Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 might allow remote attackers to execute arbitrary code via vectors involving (1) long strings in the toSource method of the Object, Array, and String objects; and (2) unspecified "string function arguments."
References (68)
Core 68
Core References
Vendor Advisory vendor-advisory
x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2006-0608.html
Third Party Advisory, US Government Resource third-party-advisory
x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/655892
Patch vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/19181
US Government Resource third-party-advisory
x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA06-208A.html
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/22055
Third Party Advisory, VDB Entry vdb-entry
signature
x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11232
Third Party Advisory, VDB Entry mailing-list
x_refsource_bugtraq
http://www.securityfocus.com/archive/1/441333/100/0/threaded
Vendor Advisory vendor-advisory
x_refsource_ubuntu
http://www.ubuntu.com/usn/usn-361-1
Vendor Advisory vendor-advisory
x_refsource_ubuntu
https://usn.ubuntu.com/329-1/
Vendor Advisory vendor-advisory
x_refsource_ubuntu
https://usn.ubuntu.com/327-1/
Vendor Advisory vendor-advisory
x_refsource_ubuntu
http://www.ubuntu.com/usn/usn-350-1
Vendor Advisory vendor-advisory
x_refsource_ubuntu
http://www.ubuntu.com/usn/usn-354-1
Third Party Advisory vendor-advisory
x_refsource_debian
http://www.debian.org/security/2006/dsa-1161
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/21243
Third Party Advisory vendor-advisory
x_refsource_debian
http://www.debian.org/security/2006/dsa-1160
Third Party Advisory vendor-advisory
x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-200608-02.xml
Vendor Advisory vendor-advisory
x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDKSA-2006:145
Third Party Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2006/3748
Third Party Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2006/2998
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/21529
Patch, Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/21216
Third Party Advisory vendor-advisory
x_refsource_gentoo
http://www.gentoo.org/security/en/glsa/glsa-200608-03.xml
Third Party Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2007/0058
Vendor Advisory vendor-advisory
x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2006-0594.html
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/21336
Third Party Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2006/3749
Vendor Advisory vendor-advisory
x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2006-0610.html
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/21654
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://securitytracker.com/id?1016588
Vendor Advisory vendor-advisory
x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDKSA-2006:146
Vendor Advisory vendor-advisory
x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2006-0609.html
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/22210
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/21634
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/21607
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://securitytracker.com/id?1016586
Patch, Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/19873
Vendor Advisory x_refsource_confirm
http://www.mozilla.org/security/announce/2006/mfsa2006-50.html
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/27987
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/21262
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/21532
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/21270
Third Party Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2008/0083
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/21361
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/21631
Third Party Advisory, VDB Entry vendor-advisory
x_refsource_hp
http://www.securityfocus.com/archive/1/446658/100/200/threaded
Third Party Advisory, VDB Entry vendor-advisory
x_refsource_hp
http://www.securityfocus.com/archive/1/446657/100/200/threaded
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/21275
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/21246
Vendor Advisory vendor-advisory
x_refsource_suse
http://www.novell.com/linux/security/advisories/2006_48_seamonkey.html
Patch, Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/21229
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/21675
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://securitytracker.com/id?1016587
Vendor Advisory vendor-advisory
x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2006-0611.html
Patch, Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/21228
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/21250
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/22342
Vendor Advisory vendor-advisory
x_refsource_sunalert
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102763-1
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/21358
Issue Tracking x_refsource_confirm
https://issues.rpath.com/browse/RPL-536
Issue Tracking x_refsource_confirm
https://issues.rpath.com/browse/RPL-537
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/22066
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/21269
Third Party Advisory vendor-advisory
x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-200608-04.xml
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/21343
Vendor Advisory vendor-advisory
x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDKSA-2006:143
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/22065
Vendor Advisory vendor-advisory
x_refsource_sgi
ftp://patches.sgi.com/support/free/security/advisories/20060703-01-U.asc
Third Party Advisory vendor-advisory
x_refsource_debian
http://www.debian.org/security/2006/dsa-1159
Scores
EPSS
0.0536
EPSS Percentile
91.8%
Details
CWE
CWE-189
Status
published
Products (11)
mozilla/firefox
1.5
mozilla/firefox
1.5.0.1
mozilla/firefox
1.5.0.2
mozilla/firefox
1.5.0.3
mozilla/firefox
1.5.0.4
mozilla/seamonkey
1.0 (2 CPE variants)
mozilla/seamonkey
1.0.1
mozilla/seamonkey
1.0.2
mozilla/thunderbird
1.5
mozilla/thunderbird
1.5.0.2
... and 1 more
Published
Jul 27, 2006
Tracked Since
Feb 18, 2026