Lucene search

K
mozillaMozilla FoundationMFSA2006-68
HistoryDec 19, 2006 - 12:00 a.m.

Crashes with evidence of memory corruption (rv:1.8.0.9/1.8.1.1) — Mozilla

2006-12-1900:00:00
Mozilla Foundation
www.mozilla.org
24

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS

0.799

Percentile

98.3%

As part of the Firefox 2.0.0.1 and 1.5.0.9 update releases we fixed several bugs to improve the stability of the product. Some of these were crashes that showed evidence of memory corruption and we presume that at least some of these could be exploited to run arbitrary code with enough effort.

Affected configurations

Vulners
Node
mozillafirefoxRange<1.5.0.9
OR
mozillafirefoxRange<2.0.0.1
OR
mozillaseamonkeyRange<1.0.7
OR
mozillathunderbirdRange<1.5.0.9
VendorProductVersionCPE
mozillafirefox*cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
mozillaseamonkey*cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:*
mozillathunderbird*cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*

References

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS

0.799

Percentile

98.3%