CVE Vulnerabilities

CVE-2006-3807

Published: Jul 27, 2006 | Modified: Oct 17, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 allows remote attackers to execute arbitrary code via script that changes the standard Object() constructor to return a reference to a privileged object and calling named JavaScript functions that use the constructor.

Affected Software

Name Vendor Start Version End Version
Seamonkey Mozilla 1.0.1 1.0.1
Firefox Mozilla 1.5.0.3 1.5.0.3
Seamonkey Mozilla 1.0 1.0
Firefox Mozilla 1.5 1.5
Seamonkey Mozilla 1.0.2 1.0.2
Thunderbird Mozilla 1.5 1.5
Thunderbird Mozilla 1.5.0.2 1.5.0.2
Firefox Mozilla 1.5.0.2 1.5.0.2
Seamonkey Mozilla 1.0 1.0
Firefox Mozilla 1.5.0.4 1.5.0.4
Firefox Mozilla 1.5.0.1 1.5.0.1
Thunderbird Mozilla 1.5.0.4 1.5.0.4

References