Lucene search

K
cveMitreCVE-2006-4253
HistoryAug 21, 2006 - 8:04 p.m.

CVE-2006-4253

2006-08-2120:04:00
CWE-264
mitre
web.nvd.nist.gov
59
cve
mozilla firefox
vulnerability
remote attackers
denial of service
arbitrary code
javascript
xml
concurrency

CVSS2

7.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:H/Au:N/C:C/I:C/A:C

AI Score

7.3

Confidence

Low

EPSS

0.966

Percentile

99.6%

Concurrency vulnerability in Mozilla Firefox 1.5.0.6 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via multiple Javascript timed events that load a deeply nested XML file, followed by redirecting the browser to another page, which leads to a concurrency failure that causes structures to be freed incorrectly, as demonstrated by (1) ffoxdie and (2) ffoxdie3. NOTE: it has been reported that Netscape 8.1 and K-Meleon 1.0.1 are also affected by ffoxdie. Mozilla confirmed to CVE that ffoxdie and ffoxdie3 trigger the same underlying vulnerability. NOTE: it was later reported that Firefox 2.0 RC2 and 1.5.0.7 are also affected.

Affected configurations

Nvd
Node
k-meleon_projectk-meleonMatch1.0.1
OR
mozillafirefoxMatch0.8
OR
mozillafirefoxMatch0.9
OR
mozillafirefoxMatch0.9rc
OR
mozillafirefoxMatch0.9.1
OR
mozillafirefoxMatch0.9.2
OR
mozillafirefoxMatch0.9.3
OR
mozillafirefoxMatch0.10
OR
mozillafirefoxMatch0.10.1
OR
mozillafirefoxMatch1.0
OR
mozillafirefoxMatch1.0.1
OR
mozillafirefoxMatch1.0.2
OR
mozillafirefoxMatch1.0.3
OR
mozillafirefoxMatch1.0.4
OR
mozillafirefoxMatch1.0.5
OR
mozillafirefoxMatch1.0.6
OR
mozillafirefoxMatch1.0.7
OR
mozillafirefoxMatch1.0.8
OR
mozillafirefoxMatch1.5
OR
mozillafirefoxMatch1.5beta1
OR
mozillafirefoxMatch1.5beta2
OR
mozillafirefoxMatch1.5.0.1
OR
mozillafirefoxMatch1.5.0.2
OR
mozillafirefoxMatch1.5.0.3
OR
mozillafirefoxMatch1.5.0.4
OR
mozillafirefoxMatch1.5.0.5
OR
mozillafirefoxMatch1.5.0.6
OR
netscapenavigatorMatch8.1
VendorProductVersionCPE
mozillafirefox1.0.6cpe:/a:mozilla:firefox:1.0.6:::
mozillafirefox0.8cpe:/a:mozilla:firefox:0.8:::
mozillafirefox1.5.0.5cpe:/a:mozilla:firefox:1.5.0.5:::
mozillafirefox1.0.5cpe:/a:mozilla:firefox:1.0.5:::
mozillafirefox1.5.0.1cpe:/a:mozilla:firefox:1.5.0.1:::
netscapenavigator8.1cpe:/a:netscape:navigator:8.1:::
mozillafirefox1.0.2cpe:/a:mozilla:firefox:1.0.2:::
mozillafirefox1.0.7cpe:/a:mozilla:firefox:1.0.7:::
mozillafirefox1.5cpe:/a:mozilla:firefox:1.5:::
mozillafirefox1.5.0.3cpe:/a:mozilla:firefox:1.5.0.3:::
Rows per page:
1-10 of 281

References

CVSS2

7.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:H/Au:N/C:C/I:C/A:C

AI Score

7.3

Confidence

Low

EPSS

0.966

Percentile

99.6%