CVE Vulnerabilities

CVE-2006-4253

Published: Aug 21, 2006 | Modified: Oct 17, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.6 HIGH
AV:N/AC:H/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

Concurrency vulnerability in Mozilla Firefox 1.5.0.6 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via multiple Javascript timed events that load a deeply nested XML file, followed by redirecting the browser to another page, which leads to a concurrency failure that causes structures to be freed incorrectly, as demonstrated by (1) ffoxdie and (2) ffoxdie3. NOTE: it has been reported that Netscape 8.1 and K-Meleon 1.0.1 are also affected by ffoxdie. Mozilla confirmed to CVE that ffoxdie and ffoxdie3 trigger the same underlying vulnerability. NOTE: it was later reported that Firefox 2.0 RC2 and 1.5.0.7 are also affected.

Affected Software

Name Vendor Start Version End Version
K-meleon K-meleon_project 1.0.1 (including) 1.0.1 (including)
Firefox Mozilla 0.8 (including) 0.8 (including)
Firefox Mozilla 0.9 (including) 0.9 (including)
Firefox Mozilla 0.9-rc (including) 0.9-rc (including)
Firefox Mozilla 0.9.1 (including) 0.9.1 (including)
Firefox Mozilla 0.9.2 (including) 0.9.2 (including)
Firefox Mozilla 0.9.3 (including) 0.9.3 (including)
Firefox Mozilla 0.10 (including) 0.10 (including)
Firefox Mozilla 0.10.1 (including) 0.10.1 (including)
Firefox Mozilla 1.0 (including) 1.0 (including)
Firefox Mozilla 1.0.1 (including) 1.0.1 (including)
Firefox Mozilla 1.0.2 (including) 1.0.2 (including)
Firefox Mozilla 1.0.3 (including) 1.0.3 (including)
Firefox Mozilla 1.0.4 (including) 1.0.4 (including)
Firefox Mozilla 1.0.5 (including) 1.0.5 (including)
Firefox Mozilla 1.0.6 (including) 1.0.6 (including)
Firefox Mozilla 1.0.7 (including) 1.0.7 (including)
Firefox Mozilla 1.0.8 (including) 1.0.8 (including)
Firefox Mozilla 1.5 (including) 1.5 (including)
Firefox Mozilla 1.5-beta1 (including) 1.5-beta1 (including)
Firefox Mozilla 1.5-beta2 (including) 1.5-beta2 (including)
Firefox Mozilla 1.5.0.1 (including) 1.5.0.1 (including)
Firefox Mozilla 1.5.0.2 (including) 1.5.0.2 (including)
Firefox Mozilla 1.5.0.3 (including) 1.5.0.3 (including)
Firefox Mozilla 1.5.0.4 (including) 1.5.0.4 (including)
Firefox Mozilla 1.5.0.5 (including) 1.5.0.5 (including)
Firefox Mozilla 1.5.0.6 (including) 1.5.0.6 (including)
Navigator Netscape 8.1 (including) 8.1 (including)
Red Hat Enterprise Linux 3 RedHat seamonkey-0:1.0.5-0.1.el3 *
Red Hat Enterprise Linux 4 RedHat firefox-0:1.5.0.7-0.1.el4 *
Red Hat Enterprise Linux 4 RedHat devhelp-0:0.10-0.4.el4 *
Red Hat Enterprise Linux 4 RedHat seamonkey-0:1.0.5-0.1.el4 *
Red Hat Enterprise Linux 4 RedHat thunderbird-0:1.5.0.7-0.1.el4 *
Firefox Ubuntu dapper *
Firefox-3.0 Ubuntu devel *
Firefox-3.0 Ubuntu gutsy *
Lightning-sunbird Ubuntu devel *
Lightning-sunbird Ubuntu gutsy *
Midbrowser Ubuntu devel *
Midbrowser Ubuntu gutsy *
Mozilla-thunderbird Ubuntu dapper *
Mozilla-thunderbird Ubuntu edgy *
Mozilla-thunderbird Ubuntu feisty *
Xulrunner Ubuntu devel *
Xulrunner Ubuntu edgy *
Xulrunner Ubuntu feisty *
Xulrunner Ubuntu gutsy *

References