CVE Vulnerabilities

CVE-2006-3806

Published: Jul 27, 2006 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Multiple integer overflows in the Javascript engine in Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 might allow remote attackers to execute arbitrary code via vectors involving (1) long strings in the toSource method of the Object, Array, and String objects; and (2) unspecified string function arguments.

Affected Software

NameVendorStart VersionEnd Version
FirefoxMozilla1.5 (including)1.5 (including)
FirefoxMozilla1.5.0.1 (including)1.5.0.1 (including)
FirefoxMozilla1.5.0.2 (including)1.5.0.2 (including)
FirefoxMozilla1.5.0.3 (including)1.5.0.3 (including)
FirefoxMozilla1.5.0.4 (including)1.5.0.4 (including)
SeamonkeyMozilla1.0 (including)1.0 (including)
SeamonkeyMozilla1.0.1 (including)1.0.1 (including)
SeamonkeyMozilla1.0.2 (including)1.0.2 (including)
ThunderbirdMozilla1.5 (including)1.5 (including)
ThunderbirdMozilla1.5.0.2 (including)1.5.0.2 (including)
ThunderbirdMozilla1.5.0.4 (including)1.5.0.4 (including)
Red Hat Enterprise Linux 3RedHatseamonkey-0:1.0.3-0.el3.1*
Red Hat Enterprise Linux 4RedHatdevhelp-0:0.10-0.2.el4*
Red Hat Enterprise Linux 4RedHatseamonkey-0:1.0.3-0.el4.1*
Red Hat Enterprise Linux 4RedHatfirefox-0:1.5.0.5-0.el4.1*
Red Hat Enterprise Linux 4RedHatthunderbird-0:1.5.0.5-0.el4.1*
Red Hat Enterprise Linux AS (Advanced Server) version 2.1RedHat*
Red Hat Enterprise Linux ES version 2.1RedHat*
Red Hat Enterprise Linux WS version 2.1RedHat*
Red Hat Linux Advanced Workstation 2.1RedHat*
FirefoxUbuntudapper*
Firefox-granparadisoUbuntudevel*
Lightning-sunbirdUbuntudevel*
MidbrowserUbuntudevel*
Mozilla-thunderbirdUbuntudapper*
Mozilla-thunderbirdUbuntuedgy*
Mozilla-thunderbirdUbuntufeisty*
XulrunnerUbuntudevel*
XulrunnerUbuntuedgy*
XulrunnerUbuntufeisty*

References