CVE-2006-6504

Mozilla Firefox <2.0.0.1 & SeaMonkey <1.0.7 - RCE

Title source: llm
STIX 2.1

Description

Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to execute arbitrary code by appending an SVG comment DOM node to another type of document, which triggers memory corruption.

References (42)

Core 42
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/21668
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/23433
Third Party Advisory vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDKSA-2007:010
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/23439
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/23672
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/5068
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/23468
Third Party Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2006-0758.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1017417
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/23692
Third Party Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/usn-398-2
Third Party Advisory vendor-advisory x_refsource_gentoo
http://www.gentoo.org/security/en/glsa/glsa-200701-04.xml
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/23282
Broken Link vendor-advisory x_refsource_fedora
http://fedoranews.org/cms/node/2297
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/23422
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/23614
Third Party Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2006-0759.html
Third Party Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/usn-398-1
Third Party Advisory, VDB Entry x_refsource_misc
http://www.zerodayinitiative.com/advisories/ZDI-06-051.html
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/0083
Broken Link vendor-advisory x_refsource_fedora
http://fedoranews.org/cms/node/2338
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/23440
Broken Link vendor-advisory x_refsource_suse
http://www.novell.com/linux/security/advisories/2006_80_mozilla.html
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/455145/100/0/threaded
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/23545
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/23618
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1017418
Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA06-354A.html
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/454939/100/0/threaded
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/23589
Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/928956
Broken Link x_refsource_confirm
https://issues.rpath.com/browse/RPL-883
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/455728/100/200/threaded
Broken Link vendor-advisory x_refsource_suse
http://www.novell.com/linux/security/advisories/2007_06_mozilla.html
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/23601
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/23514
Third Party Advisory vendor-advisory x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-200701-02.xml
Third Party Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2006-0760.html

Scores

EPSS 0.0860
EPSS Percentile 94.4%

Details

CWE
CWE-94
Status published
Products (5)
canonical/ubuntu_linux 5.10
canonical/ubuntu_linux 6.06
canonical/ubuntu_linux 6.10
mozilla/firefox 1.5 - 1.5.0.9
mozilla/seamonkey < 1.0.7
Published Dec 20, 2006
Tracked Since Feb 18, 2026