First published: Fri Apr 14 2006(Updated: )
A regression fix in Mozilla Firefox 1.0.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the InstallTrigger.install method, which leads to memory corruption.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | =1.0.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-1790 is categorized as a high-severity vulnerability due to its potential to cause denial of service and arbitrary code execution.
To fix CVE-2006-1790, upgrade to Mozilla Firefox versions newer than 1.0.7 that have patched this vulnerability.
CVE-2006-1790 enables remote attackers to execute arbitrary code or cause a crash in affected versions of Mozilla Firefox.
CVE-2006-1790 specifically affects Mozilla Firefox version 1.0.7.
Yes, CVE-2006-1790 can be exploited by remote attackers, typically without requiring user interaction.