CVE-2006-6504: Code Injection
Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to execute arbitrary code by appending an SVG comment DOM node to another type of document, which triggers memory corruption.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-6504?
CVE-2006-6504 is classified as a critical vulnerability due to its potential to allow remote code execution.
How do I fix CVE-2006-6504?
To fix CVE-2006-6504, users should upgrade to Mozilla Firefox versions 2.0.0.1 or higher, 1.5.0.9 or higher, or SeaMonkey 1.0.7 or higher.
What software is affected by CVE-2006-6504?
CVE-2006-6504 affects Mozilla Firefox versions 1.5.x before 1.5.0.9, versions 2.x before 2.0.0.1, and SeaMonkey versions before 1.0.7.
Can CVE-2006-6504 be exploited remotely?
Yes, CVE-2006-6504 can be exploited by remote attackers to execute arbitrary code.
What type of vulnerability is CVE-2006-6504?
CVE-2006-6504 is a memory corruption vulnerability triggered by manipulating SVG comments.