CVE-2006-5747

Mozilla Firefox, Thunderbird, and SeaMonkey - Remote Code Execution via XML.prototype.hasOwnProperty

Title source: llm
STIX 2.1

Description

Unspecified vulnerability in Mozilla Firefox before 1.5.0.8, Thunderbird before 1.5.0.8, and SeaMonkey before 1.0.6 allows remote attackers to execute arbitrary code via the XML.prototype.hasOwnProperty JavaScript function.

References (48)

Core 48
Core References
Issue Tracking x_refsource_misc
https://bugzilla.mozilla.org/show_bug.cgi?id=355569
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/3748
Patch vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1017178
Patch vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1017179
Patch, Vendor Advisory vendor-advisory x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-200612-08.xml
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/23013
Patch, Vendor Advisory x_refsource_confirm
http://support.avaya.com/elmodocs2/security/ASA-2006-246.htm
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/451099/100/0/threaded
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/22770
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/4387
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/30093
Issue Tracking x_refsource_confirm
https://issues.rpath.com/browse/RPL-765
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/23009
Patch, US Government Resource third-party-advisory x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA06-312A.html
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/22980
Patch, Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2006-0733.html
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/24711
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/23263
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/22763
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/22965
Patch, Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/usn-382-1
Patch vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1017177
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/0083
Patch, Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2006-0735.html
Patch, Vendor Advisory vendor-advisory x_refsource_suse
http://www.novell.com/linux/security/advisories/2006_68_mozilla.html
Patch, Vendor Advisory vendor-advisory x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-200612-07.xml
Patch, US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/815432
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2007/1198
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/23297
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/22727
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/22815
Patch, Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2006-0734.html
Various Sources vendor-advisory x_refsource_hp
http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00771742
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/22737
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/22929
Patch, Vendor Advisory vendor-advisory x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-200612-06.xml
Vendor Advisory vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDKSA-2006:206
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/20957
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/22066
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/22774
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11496
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/22817
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/22722
Vendor Advisory vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDKSA-2006:205
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/23287
Patch, Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/usn-381-1

Scores

EPSS 0.0553
EPSS Percentile 91.9%

Details

Status published
Products (25)
mozilla/firefox 1.5 (3 CPE variants)
mozilla/firefox 1.5.0.1
mozilla/firefox 1.5.0.2
mozilla/firefox 1.5.0.3
mozilla/firefox 1.5.0.4
mozilla/firefox 1.5.0.5
mozilla/firefox 1.5.0.6
mozilla/firefox 1.5.0.7
mozilla/seamonkey 1.0 (2 CPE variants)
mozilla/seamonkey 1.0.1
... and 15 more
Published Nov 08, 2006
Tracked Since Feb 18, 2026