First published: Thu Jul 27 2006(Updated: )
Mozilla Firefox 1.5 before 1.5.0.5 and SeaMonkey before 1.0.3 allows remote attackers to execute arbitrary code by changing certain properties of the window navigator object (window.navigator) that are accessed when Java starts up, which causes a crash that leads to code execution.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Firefox | =1.5 | |
Firefox | =1.5.0.1 | |
Firefox | =1.5.0.2 | |
Firefox | =1.5.0.3 | |
Firefox | =1.5.0.4 | |
Mozilla SeaMonkey | =1.0 | |
Mozilla SeaMonkey | =1.0 | |
Mozilla SeaMonkey | =1.0.1 | |
Mozilla SeaMonkey | =1.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-3677 is classified as a critical vulnerability due to its potential for remote code execution.
CVE-2006-3677 affects Mozilla Firefox versions 1.5 before 1.5.0.5 and SeaMonkey versions before 1.0.3.
To remediate CVE-2006-3677, update your Mozilla Firefox to version 1.5.0.5 or later, or SeaMonkey to version 1.0.3 or later.
CVE-2006-3677 can be exploited by remote attackers to execute arbitrary code through a manipulated window navigator object.
There is no official workaround for CVE-2006-3677; the best mitigation is to upgrade to the patched versions.