← All CVEs

CVE-2006-3677

high · 7.5

Mozilla Firefox 1.5 before 1.5.0.5 and SeaMonkey before 1.0.3 allows remote attackers to execute arbitrary code by changing certain properties of the window navigator object (window.navigator) that are accessed when Java starts up, which causes a crash that leads to code execution.

7.5
CVSS
78.7%
EPSS (exploit prob.)
100th
EPSS percentile
2006-07-27
Published

AV:N/AC:L/Au:N/C:P/I:P/A:P

Weaknesses

CWE-16

Affected products

VendorProductAffected versions
mozillafirefox1.5
mozillafirefox1.5.0.1
mozillafirefox1.5.0.2
mozillafirefox1.5.0.3
mozillafirefox1.5.0.4
mozillaseamonkey1.0
mozillaseamonkey1.0
mozillaseamonkey1.0.1
mozillaseamonkey1.0.2

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2006-3677