CVE-2006-2779: Code Injection
Mozilla Firefox and Thunderbird before 1.5.0.4 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) nested <option> tags in a select tag, (2) a DOMNodeRemoved mutation event, (3) "Content-implemented tree views," (4) BoxObjects, (5) the XBL implementation, (6) an iframe that attempts to remove itself, which leads to memory corruption.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-2779?
The severity of CVE-2006-2779 is high, as it can lead to denial of service and possible arbitrary code execution.
How do I fix CVE-2006-2779?
To fix CVE-2006-2779, update to Mozilla Firefox or Thunderbird versions 1.5.0.4 or later.
What versions of Mozilla Firefox are affected by CVE-2006-2779?
Affected versions of Mozilla Firefox include version 0.8, 0.9, 1.0, and 1.5 up to 1.5.0.3.
What versions of Thunderbird are affected by CVE-2006-2779?
Affected versions of Mozilla Thunderbird include version 0.6, 0.7, 0.8, and 1.0 up to 1.5.0.3.
What types of vulnerabilities does CVE-2006-2779 exploit?
CVE-2006-2779 exploits vulnerabilities through nested <option> tags, DOMNodeRemoved mutation events, and other DOM manipulation methods.