CVE Vulnerabilities

CVE-2006-3803

Published: Jul 27, 2006 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.1 MEDIUM
AV:N/AC:H/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Race condition in the JavaScript garbage collection in Mozilla Firefox 1.5 before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 might allow remote attackers to execute arbitrary code by causing the garbage collector to delete a temporary variable while it is still being used during the creation of a new Function object.

Affected Software

NameVendorStart VersionEnd Version
FirefoxMozilla1.5 (including)1.5 (including)
FirefoxMozilla1.5.0.1 (including)1.5.0.1 (including)
FirefoxMozilla1.5.0.2 (including)1.5.0.2 (including)
FirefoxMozilla1.5.0.3 (including)1.5.0.3 (including)
FirefoxMozilla1.5.0.4 (including)1.5.0.4 (including)
SeamonkeyMozilla1.0 (including)1.0 (including)
SeamonkeyMozilla1.0.1 (including)1.0.1 (including)
SeamonkeyMozilla1.0.2 (including)1.0.2 (including)
ThunderbirdMozilla1.5 (including)1.5 (including)
ThunderbirdMozilla1.5.0.2 (including)1.5.0.2 (including)
ThunderbirdMozilla1.5.0.4 (including)1.5.0.4 (including)
Red Hat Enterprise Linux 3RedHatseamonkey-0:1.0.3-0.el3.1*
Red Hat Enterprise Linux 4RedHatdevhelp-0:0.10-0.2.el4*
Red Hat Enterprise Linux 4RedHatseamonkey-0:1.0.3-0.el4.1*
Red Hat Enterprise Linux 4RedHatfirefox-0:1.5.0.5-0.el4.1*
Red Hat Enterprise Linux 4RedHatthunderbird-0:1.5.0.5-0.el4.1*
Red Hat Enterprise Linux AS (Advanced Server) version 2.1RedHat*
Red Hat Enterprise Linux ES version 2.1RedHat*
Red Hat Enterprise Linux WS version 2.1RedHat*
Red Hat Linux Advanced Workstation 2.1RedHat*
FirefoxUbuntudapper*
Firefox-granparadisoUbuntudevel*
Lightning-sunbirdUbuntudevel*
MidbrowserUbuntudevel*
Mozilla-thunderbirdUbuntudapper*
Mozilla-thunderbirdUbuntuedgy*
Mozilla-thunderbirdUbuntufeisty*
XulrunnerUbuntudevel*
XulrunnerUbuntuedgy*
XulrunnerUbuntufeisty*

References