First published: Wed Dec 20 2006(Updated: )
Multiple unspecified vulnerabilities in the layout engine for Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 allow remote attackers to cause a denial of service (memory corruption and crash) and possibly execute arbitrary code via unknown attack vectors.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Firefox | <=1.5.0.8 | |
Mozilla SeaMonkey | <=1.5.0.8 | |
Thunderbird | <=1.5.0.8 | |
Firefox | =2.0 | |
<=1.5.0.8 | ||
=2.0 | ||
<=1.5.0.8 | ||
<=1.5.0.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-6497 has a high severity rating due to the potential for remote code execution and denial of service.
To fix CVE-2006-6497, update affected Mozilla Firefox, SeaMonkey, or Thunderbird to the latest version that is not vulnerable.
CVE-2006-6497 affects Mozilla Firefox versions before 2.0.0.1 and 1.5.x before 1.5.0.9, as well as Thunderbird and SeaMonkey versions before their respective updates.
Yes, CVE-2006-6497 can potentially allow remote attackers to execute arbitrary code on vulnerable installations.
CVE-2006-6497 impacts Mozilla Firefox, Thunderbird, and SeaMonkey web browsers.