← All CVEs

CVE-2006-0749

high · 9.3

nsHTMLContentSink.cpp in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors involving a "particular sequence of HTML tags" that leads to memory corruption.

9.3
CVSS
10.5%
EPSS (exploit prob.)
96th
EPSS percentile
2006-04-14
Published

AV:N/AC:M/Au:N/C:C/I:C/A:C

Weaknesses

CWE-399

Affected products

VendorProductAffected versions
mozillafirefox>= 1.0, < 1.5
mozillamozilla_suite< 1.7.13
mozillaseamonkey< 1.0
mozillathunderbird>= 1.0, < 1.0.8

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2006-0749