CVE-2006-0298: Input Validation
Published Feb 2, 2006
·Updated
The XML parser in Mozilla Firefox before 1.5.0.1 and SeaMonkey before 1.0 allows remote attackers to cause a denial of service (crash) and possibly read sensitive data via unknown attack vectors that trigger an out-of-bounds read.
Affected Software
4 affected components
Mozilla Firefox=1.5
Mozilla Firefox=1.5-beta1
Mozilla SeaMonkey=1.0
Mozilla SeaMonkey=1.0-beta
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Feb 2, 2006
CVE Published
10:02 PM
Feb 3, 2006
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-0298?
CVE-2006-0298 has a severity rating of moderate due to its potential to cause a denial of service.
2
How do I fix CVE-2006-0298?
To fix CVE-2006-0298, update Mozilla Firefox and SeaMonkey to the latest version available.
3
Which versions of software are affected by CVE-2006-0298?
CVE-2006-0298 affects Mozilla Firefox versions before 1.5.0.1 and SeaMonkey versions before 1.0.
4
What type of vulnerability is CVE-2006-0298?
CVE-2006-0298 is a denial of service vulnerability that can also potentially allow unauthorized reading of sensitive data.
5
Can CVE-2006-0298 be exploited remotely?
Yes, CVE-2006-0298 can be exploited remotely by attackers to crash the affected software.