CVE-2006-1733: Medium severity Mozilla Firefox vulnerability
Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 does not properly protect the compilation scope of privileged built-in XBL bindings, which allows remote attackers to execute arbitrary code via the (1) valueOf.call or (2) valueOf.apply methods of an XBL binding, or (3) "by inserting an XBL method into the DOM's document.body prototype chain."
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2006-1733?
CVE-2006-1733 is classified as a critical vulnerability that allows remote code execution.
How do I fix CVE-2006-1733?
To fix CVE-2006-1733, you should update affected Mozilla products to the latest versions that contain the security patches.
What versions of Firefox are affected by CVE-2006-1733?
Versions of Firefox prior to 1.5 and specifically those in the 1.0.x branch before 1.0.8 are affected by CVE-2006-1733.
Is CVE-2006-1733 applicable to Thunderbird users?
Yes, CVE-2006-1733 affects Thunderbird versions before 1.5, including 1.0.x versions.
Can CVE-2006-1733 be exploited remotely?
Yes, CVE-2006-1733 can be exploited remotely, enabling attackers to execute arbitrary code on the user's machine.