Description
Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to execute arbitrary code by appending an SVG comment DOM node to another type of document, which triggers memory corruption.
References (42)
Core 42
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/21668
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/23433
Third Party Advisory vendor-advisory
x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDKSA-2007:010
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/23439
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/23672
Third Party Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2006/5068
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/23468
Third Party Advisory vendor-advisory
x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2006-0758.html
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://securitytracker.com/id?1017417
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/23692
Third Party Advisory vendor-advisory
x_refsource_ubuntu
http://www.ubuntu.com/usn/usn-398-2
Third Party Advisory vendor-advisory
x_refsource_gentoo
http://www.gentoo.org/security/en/glsa/glsa-200701-04.xml
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/23282
Broken Link vendor-advisory
x_refsource_fedora
http://fedoranews.org/cms/node/2297
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/23422
Broken Link vendor-advisory
x_refsource_hp
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742
Vendor Advisory x_refsource_confirm
http://www.mozilla.org/security/announce/2006/mfsa2006-73.html
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/23614
Third Party Advisory vendor-advisory
x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2006-0759.html
Third Party Advisory vdb-entry
signature
x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11077
Third Party Advisory vendor-advisory
x_refsource_ubuntu
http://www.ubuntu.com/usn/usn-398-1
Third Party Advisory, VDB Entry x_refsource_misc
http://www.zerodayinitiative.com/advisories/ZDI-06-051.html
Third Party Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2008/0083
Broken Link vendor-advisory
x_refsource_fedora
http://fedoranews.org/cms/node/2338
Broken Link vendor-advisory
x_refsource_sgi
ftp://patches.sgi.com/support/free/security/advisories/20061202-01-P.asc
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/23440
Broken Link vendor-advisory
x_refsource_suse
http://www.novell.com/linux/security/advisories/2006_80_mozilla.html
Third Party Advisory, VDB Entry mailing-list
x_refsource_bugtraq
http://www.securityfocus.com/archive/1/455145/100/0/threaded
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/23545
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/23618
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://securitytracker.com/id?1017418
Third Party Advisory, US Government Resource third-party-advisory
x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA06-354A.html
Third Party Advisory, VDB Entry mailing-list
x_refsource_bugtraq
http://www.securityfocus.com/archive/1/454939/100/0/threaded
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/23589
Third Party Advisory, US Government Resource third-party-advisory
x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/928956
Broken Link x_refsource_confirm
https://issues.rpath.com/browse/RPL-883
Third Party Advisory, VDB Entry mailing-list
x_refsource_bugtraq
http://www.securityfocus.com/archive/1/455728/100/200/threaded
Broken Link vendor-advisory
x_refsource_suse
http://www.novell.com/linux/security/advisories/2007_06_mozilla.html
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/23601
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/23514
Third Party Advisory vendor-advisory
x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-200701-02.xml
Third Party Advisory vendor-advisory
x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2006-0760.html
Scores
EPSS
0.0860
EPSS Percentile
94.4%
Details
CWE
CWE-94
Status
published
Products (5)
canonical/ubuntu_linux
5.10
canonical/ubuntu_linux
6.06
canonical/ubuntu_linux
6.10
mozilla/firefox
1.5 - 1.5.0.9
mozilla/seamonkey
< 1.0.7
Published
Dec 20, 2006
Tracked Since
Feb 18, 2026