CVE-2006-6504

CVSS V2 High 9.3 CVSS V3 None
Description
Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to execute arbitrary code by appending an SVG comment DOM node to another type of document, which triggers memory corruption.
Overview
  • CVE ID
  • CVE-2006-6504
  • Assigner
  • secalert@redhat.com
  • Vulnerability Status
  • Modified
  • Published Version
  • 2006-12-20T01:28:00
  • Last Modified Date
  • 2018-10-17T21:48:53
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* 1 OR 1.5 1.5.0.9
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* 1 OR 2.0 2.0.0.1
cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:* 1 OR 1.0.7
cpe:2.3:o:canonical:ubuntu_linux:5.10:*:*:*:*:*:*:* 1 OR
cpe:2.3:o:canonical:ubuntu_linux:6.06:*:*:*:lts:*:*:* 1 OR
cpe:2.3:o:canonical:ubuntu_linux:6.10:*:*:*:*:*:*:* 1 OR
CVSS Version 2
  • Version
  • 2.0
  • Vector String
  • AV:N/AC:M/Au:N/C:C/I:C/A:C
  • Access Vector
  • NETWORK
  • Access Compatibility
  • MEDIUM
  • Authentication
  • NONE
  • Confidentiality Impact
  • COMPLETE
  • Integrity Impact
  • COMPLETE
  • Availability Impact
  • COMPLETE
  • Base Score
  • 9.3
  • Severity
  • HIGH
  • Exploitability Score
  • 8.6
  • Impact Score
  • 10
References
Reference URL Reference Tags
http://www.mozilla.org/security/announce/2006/mfsa2006-73.html Vendor Advisory
http://www.zerodayinitiative.com/advisories/ZDI-06-051.html Third Party Advisory VDB Entry
http://rhn.redhat.com/errata/RHSA-2006-0758.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2006-0759.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2006-0760.html Third Party Advisory
http://securitytracker.com/id?1017417 Third Party Advisory VDB Entry
http://securitytracker.com/id?1017418 Third Party Advisory VDB Entry
http://secunia.com/advisories/23433 Third Party Advisory
http://secunia.com/advisories/23439 Third Party Advisory
http://secunia.com/advisories/23440 Third Party Advisory
https://issues.rpath.com/browse/RPL-883 Broken Link
http://www.us-cert.gov/cas/techalerts/TA06-354A.html Third Party Advisory US Government Resource
http://www.kb.cert.org/vuls/id/928956 Third Party Advisory US Government Resource
http://www.securityfocus.com/bid/21668 Third Party Advisory VDB Entry
http://secunia.com/advisories/23282 Third Party Advisory
http://secunia.com/advisories/23422 Third Party Advisory
http://secunia.com/advisories/23468 Third Party Advisory
ftp://patches.sgi.com/support/free/security/advisories/20061202-01-P.asc Broken Link
http://secunia.com/advisories/23514 Third Party Advisory
http://www.novell.com/linux/security/advisories/2006_80_mozilla.html Broken Link
http://www.ubuntu.com/usn/usn-398-1 Third Party Advisory
http://secunia.com/advisories/23589 Third Party Advisory
http://fedoranews.org/cms/node/2297 Broken Link
http://fedoranews.org/cms/node/2338 Broken Link
http://security.gentoo.org/glsa/glsa-200701-02.xml Third Party Advisory
http://www.ubuntu.com/usn/usn-398-2 Third Party Advisory
http://secunia.com/advisories/23601 Third Party Advisory
http://secunia.com/advisories/23545 Third Party Advisory
http://secunia.com/advisories/23614 Third Party Advisory
http://secunia.com/advisories/23618 Third Party Advisory
http://www.gentoo.org/security/en/glsa/glsa-200701-04.xml Third Party Advisory
http://secunia.com/advisories/23692 Third Party Advisory
http://www.novell.com/linux/security/advisories/2007_06_mozilla.html Broken Link
http://secunia.com/advisories/23672 Third Party Advisory
http://www.mandriva.com/security/advisories?name=MDKSA-2007:010 Third Party Advisory
http://www.vupen.com/english/advisories/2008/0083 Third Party Advisory
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742 Broken Link
http://www.vupen.com/english/advisories/2006/5068 Third Party Advisory
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11077 Third Party Advisory
http://www.securityfocus.com/archive/1/455728/100/200/threaded
http://www.securityfocus.com/archive/1/455145/100/0/threaded
http://www.securityfocus.com/archive/1/454939/100/0/threaded
History
Created Old Value New Value Data Type Notes
2022-05-10 18:10:30 Added to TrackCVE