CVE-2006-2780: Code Injection
Published Jun 2, 2006
·Updated
Integer overflow in Mozilla Firefox and Thunderbird before 1.5.0.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via "jsstr tagify," which leads to memory corruption.
Affected Software
2 affected components
Mozilla Firefox<=1.5.0.3
Mozilla Thunderbird<=1.5.0.3
Event History
Jun 2, 2006
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
Which deployments should be considered exposed?
Mozilla Firefox and Mozilla Thunderbird versions before 1.5.0.4 are affected.
2
Does an attacker need an account or prior authentication to exploit this issue?
No. The vector is network-based and the authentication requirement is listed as none.
3
What is the potential consequence beyond service disruption?
The integer overflow can cause memory corruption, leading to a crash and possibly arbitrary code execution.