CVE-2006-3811: Buffer Overflow
Multiple vulnerabilities in Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via Javascript that leads to memory corruption, including (1) nsListControlFrame::FireMenuItemActiveEvent, (2) buffer overflows in the string class in out-of-memory conditions, (3) table row and column groups, (4) "anonymous box selectors outside of UA stylesheets," (5) stale references to "removed nodes," and (6) running the crypto.generateCRMFRequest callback on deleted context.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-3811?
CVE-2006-3811 has a medium severity rating due to its potential for remote code execution and denial of service.
How do I fix CVE-2006-3811?
To remediate CVE-2006-3811, update Mozilla Firefox, Thunderbird, or SeaMonkey to versions 1.5.0.5, 1.5.0.5, or 1.0.3 respectively.
Which software is affected by CVE-2006-3811?
CVE-2006-3811 affects Mozilla Firefox versions prior to 1.5.0.5, Thunderbird versions before 1.5.0.5, and SeaMonkey versions earlier than 1.0.3.
What are the potential impacts of CVE-2006-3811?
The potential impacts of CVE-2006-3811 include crashing the browser and allowing attackers to execute arbitrary code.
Is CVE-2006-3811 still relevant?
While CVE-2006-3811 pertains to older software, it remains relevant for users of unpatched versions.