Lucene search

K
cveRedhatCVE-2006-0297
HistoryFeb 02, 2006 - 10:02 p.m.

CVE-2006-0297

2006-02-0222:02:00
redhat
web.nvd.nist.gov
111
cve-2006-0297
mozilla firefox
thunderbird
seamonkey
integer overflow
remote code execution
nvd

CVSS2

5.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:P/I:P/A:P

AI Score

7.3

Confidence

High

EPSS

0.93

Percentile

99.0%

Multiple integer overflows in Mozilla Firefox 1.5, Thunderbird 1.5 if Javascript is enabled in mail, and SeaMonkey before 1.0 might allow remote attackers to execute arbitrary code via the (1) EscapeAttributeValue in jsxml.c for E4X, (2) nsSVGCairoSurface::Init in SVG, and (3) nsCanvasRenderingContext2D.cpp in Canvas.

Affected configurations

Nvd
Node
mozillafirefoxMatch1.5
OR
mozillafirefoxMatch1.5beta1
OR
mozillaseamonkeyMatch1.0alpha
OR
mozillaseamonkeyMatch1.0beta
OR
mozillathunderbirdMatch1.5
VendorProductVersionCPE
mozillafirefox1.5cpe:2.3:a:mozilla:firefox:1.5:*:*:*:*:*:*:*
mozillafirefox1.5cpe:2.3:a:mozilla:firefox:1.5:beta1:*:*:*:*:*:*
mozillaseamonkey1.0cpe:2.3:a:mozilla:seamonkey:1.0:*:alpha:*:*:*:*:*
mozillaseamonkey1.0cpe:2.3:a:mozilla:seamonkey:1.0:beta:*:*:*:*:*:*
mozillathunderbird1.5cpe:2.3:a:mozilla:thunderbird:1.5:*:*:*:*:*:*:*

CVSS2

5.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:P/I:P/A:P

AI Score

7.3

Confidence

High

EPSS

0.93

Percentile

99.0%