First published: Fri Jun 02 2006(Updated: )
Mozilla Firefox and Thunderbird before 1.5.0.4 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) nested <option> tags in a select tag, (2) a DOMNodeRemoved mutation event, (3) "Content-implemented tree views," (4) BoxObjects, (5) the XBL implementation, (6) an iframe that attempts to remove itself, which leads to memory corruption.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Thunderbird | =0.6 | |
Mozilla Firefox | =0.8 | |
Mozilla Thunderbird | =0.7.2 | |
Mozilla Firefox | =1.5-beta2 | |
Mozilla Firefox | =1.5.2 | |
Mozilla Thunderbird | =1.0.7 | |
Mozilla Firefox | =1.0.2 | |
Mozilla Firefox | =1.5-beta1 | |
Mozilla Firefox | =1.5 | |
Mozilla Firefox | =0.9.1 | |
Mozilla Firefox | =1.0.4 | |
Mozilla Firefox | =1.0.7 | |
Mozilla Firefox | =0.10.1 | |
Mozilla Thunderbird | =1.0 | |
Mozilla Firefox | =0.9 | |
Mozilla Thunderbird | =1.0.1 | |
Mozilla Thunderbird | =1.5-beta2 | |
Mozilla Thunderbird | =1.0.2 | |
Mozilla Firefox | =1.0 | |
Mozilla Thunderbird | =1.5 | |
Mozilla Firefox | =1.0.1 | |
Mozilla Firefox | =preview_release | |
Mozilla Thunderbird | =1.5.2 | |
Mozilla Thunderbird | =0.9 | |
Mozilla Firefox | =1.5.0.2 | |
Mozilla Firefox | =1.0.3 | |
Mozilla Firefox | =1.5.1 | |
Mozilla Thunderbird | =0.7.3 | |
Mozilla Firefox | =0.9.3 | |
Mozilla Thunderbird | =1.5.1 | |
Mozilla Thunderbird | =0.7 | |
Mozilla Thunderbird | =1.0.6 | |
Mozilla Firefox | =0.9.2 | |
Mozilla Thunderbird | =1.0.8 | |
Mozilla Firefox | =0.9-rc | |
Mozilla Firefox | =1.5.3 | |
Mozilla Thunderbird | =0.7.1 | |
Mozilla Thunderbird | =1.0.5 | |
Mozilla Thunderbird | =0.8 | |
Mozilla Firefox | =0.10 | |
Mozilla Firefox | =1.0.5 | |
Mozilla Firefox | =1.0.6 | |
Mozilla Firefox | =1.0.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2006-2779 is high, as it can lead to denial of service and possible arbitrary code execution.
To fix CVE-2006-2779, update to Mozilla Firefox or Thunderbird versions 1.5.0.4 or later.
Affected versions of Mozilla Firefox include version 0.8, 0.9, 1.0, and 1.5 up to 1.5.0.3.
Affected versions of Mozilla Thunderbird include version 0.6, 0.7, 0.8, and 1.0 up to 1.5.0.3.
CVE-2006-2779 exploits vulnerabilities through nested <option> tags, DOMNodeRemoved mutation events, and other DOM manipulation methods.