CVE-2006-3677
high · 7.5Mozilla Firefox 1.5 before 1.5.0.5 and SeaMonkey before 1.0.3 allows remote attackers to execute arbitrary code by changing certain properties of the window navigator object (window.navigator) that are accessed when Java starts up, which causes a crash that leads to code execution.
7.5
CVSS
78.7%
EPSS (exploit prob.)
100th
EPSS percentile
2006-07-27
Published
AV:N/AC:L/Au:N/C:P/I:P/A:P
Weaknesses
CWE-16
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| mozilla | firefox | 1.5 |
| mozilla | firefox | 1.5.0.1 |
| mozilla | firefox | 1.5.0.2 |
| mozilla | firefox | 1.5.0.3 |
| mozilla | firefox | 1.5.0.4 |
| mozilla | seamonkey | 1.0 |
| mozilla | seamonkey | 1.0 |
| mozilla | seamonkey | 1.0.1 |
| mozilla | seamonkey | 1.0.2 |
Check a specific version with /api/v1/cve/match.
References
- ftp://patches.sgi.com/support/free/security/advisories/20060703-01-U.asc
- http://rhn.redhat.com/errata/RHSA-2006-0609.html
- http://secunia.com/advisories/19873
- http://secunia.com/advisories/21216
- http://secunia.com/advisories/21229
- http://secunia.com/advisories/21243
- http://secunia.com/advisories/21246
- http://secunia.com/advisories/21262
- http://secunia.com/advisories/21269
- http://secunia.com/advisories/21270
- http://secunia.com/advisories/21336
- http://secunia.com/advisories/21343
- http://secunia.com/advisories/21361
- http://secunia.com/advisories/21529
- http://secunia.com/advisories/21532
- http://secunia.com/advisories/21631
- http://secunia.com/advisories/22066
- http://secunia.com/advisories/22210
- http://security.gentoo.org/glsa/glsa-200608-02.xml
- http://securitytracker.com/id?1016586
- http://securitytracker.com/id?1016587
- http://www.gentoo.org/security/en/glsa/glsa-200608-03.xml
- http://www.kb.cert.org/vuls/id/670060
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:143
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:145
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2006-3677