CVE Vulnerabilities

CVE-2006-3801

Published: Jul 27, 2006 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Mozilla Firefox 1.5 before 1.5.0.5 and SeaMonkey before 1.0.3 does not properly clear a JavaScript reference to a frame or window, which leaves a pointer to a deleted object that allows remote attackers to execute arbitrary native code.

Affected Software

NameVendorStart VersionEnd Version
FirefoxMozilla1.5 (including)1.5 (including)
FirefoxMozilla1.5.0.1 (including)1.5.0.1 (including)
FirefoxMozilla1.5.0.2 (including)1.5.0.2 (including)
FirefoxMozilla1.5.0.3 (including)1.5.0.3 (including)
FirefoxMozilla1.5.0.4 (including)1.5.0.4 (including)
SeamonkeyMozilla1.0 (including)1.0 (including)
SeamonkeyMozilla1.0.1 (including)1.0.1 (including)
SeamonkeyMozilla1.0.2 (including)1.0.2 (including)
Red Hat Enterprise Linux 3RedHatseamonkey-0:1.0.3-0.el3.1*
Red Hat Enterprise Linux 4RedHatdevhelp-0:0.10-0.2.el4*
Red Hat Enterprise Linux 4RedHatseamonkey-0:1.0.3-0.el4.1*
Red Hat Enterprise Linux 4RedHatfirefox-0:1.5.0.5-0.el4.1*
Red Hat Enterprise Linux 4RedHatthunderbird-0:1.5.0.5-0.el4.1*
Red Hat Enterprise Linux AS (Advanced Server) version 2.1RedHat*
Red Hat Enterprise Linux ES version 2.1RedHat*
Red Hat Enterprise Linux WS version 2.1RedHat*
Red Hat Linux Advanced Workstation 2.1RedHat*
FirefoxUbuntudapper*
Firefox-granparadisoUbuntudevel*
Lightning-sunbirdUbuntudevel*
MidbrowserUbuntudevel*
XulrunnerUbuntudevel*
XulrunnerUbuntuedgy*
XulrunnerUbuntufeisty*

References