CVE Vulnerabilities

CVE-2006-4253

Published: Aug 21, 2006 | Modified: Oct 17, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.6 HIGH
AV:N/AC:H/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

Concurrency vulnerability in Mozilla Firefox 1.5.0.6 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via multiple Javascript timed events that load a deeply nested XML file, followed by redirecting the browser to another page, which leads to a concurrency failure that causes structures to be freed incorrectly, as demonstrated by (1) ffoxdie and (2) ffoxdie3. NOTE: it has been reported that Netscape 8.1 and K-Meleon 1.0.1 are also affected by ffoxdie. Mozilla confirmed to CVE that ffoxdie and ffoxdie3 trigger the same underlying vulnerability. NOTE: it was later reported that Firefox 2.0 RC2 and 1.5.0.7 are also affected.

Affected Software

Name Vendor Start Version End Version
Firefox Mozilla 0.8 0.8
Firefox Mozilla 1.5 1.5
Firefox Mozilla 1.5.0.6 1.5.0.6
Firefox Mozilla 1.5.0.3 1.5.0.3
Navigator Netscape 8.1 8.1
Firefox Mozilla 1.0.2 1.0.2
Firefox Mozilla 1.5 1.5
Firefox Mozilla 1.5 1.5
Firefox Mozilla 0.9.1 0.9.1
Firefox Mozilla 1.0.4 1.0.4
Firefox Mozilla 1.0.7 1.0.7
Firefox Mozilla 0.10.1 0.10.1
Firefox Mozilla 0.9 0.9
K-meleon K-meleon_project 1.0.1 1.0.1
Firefox Mozilla 1.0 1.0
Firefox Mozilla 1.0.1 1.0.1
Firefox Mozilla 1.5.0.5 1.5.0.5
Firefox Mozilla 1.5.0.2 1.5.0.2
Firefox Mozilla 1.0.3 1.0.3
Firefox Mozilla 0.9.3 0.9.3
Firefox Mozilla 0.9.2 0.9.2
Firefox Mozilla 0.9 0.9
Firefox Mozilla 1.5.0.4 1.5.0.4
Firefox Mozilla 1.5.0.1 1.5.0.1
Firefox Mozilla 0.10 0.10
Firefox Mozilla 1.0.5 1.0.5
Firefox Mozilla 1.0.6 1.0.6
Firefox Mozilla 1.0.8 1.0.8

References