First published: Fri Apr 14 2006(Updated: )
nsHTMLContentSink.cpp in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors involving a "particular sequence of HTML tags" that leads to memory corruption.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox and Thunderbird | >=1.0<=1.5 | |
Mozilla Suite | <1.7.13 | |
Mozilla SeaMonkey | <1.0 | |
Mozilla Firefox and Thunderbird | >=1.0<1.0.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-0749 is classified as a denial of service vulnerability that can potentially allow the execution of arbitrary code.
To fix CVE-2006-0749, update to the latest version of Mozilla Firefox, Thunderbird, Mozilla Suite, or SeaMonkey that is not affected by this vulnerability.
CVE-2006-0749 affects Mozilla Firefox versions before 1.5, Thunderbird versions before 1.0.8, Mozilla Suite versions before 1.7.13, and SeaMonkey versions before 1.0.
Yes, an exploit of CVE-2006-0749 could lead to a crash of the application and potential data loss for unsaved user data.
Attackers can exploit CVE-2006-0749 using unknown vectors that trigger a specific sequence within affected versions of the software.