CVE-2006-4253
high · 7.6Concurrency vulnerability in Mozilla Firefox 1.5.0.6 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via multiple Javascript timed events that load a deeply nested XML file, followed by redirecting the browser to another page, which leads to a concurrency failure that causes structures to be freed incorrectly, as demonstrated by (1) ffoxdie and (2) ffoxdie3. NOTE: it has been reported that Netscape 8.1 and K-Meleon 1.0.1 are also affected by ffoxdie. Mozilla confirmed to CVE that ffoxdie and ffoxdie3 trigger the same underlying vulnerability. NOTE: it was later reported that Firefox 2.0 RC2 and 1.5.0.7 are also affected.
AV:N/AC:H/Au:N/C:C/I:C/A:C
Weaknesses
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| k-meleon_project | k-meleon | 1.0.1 |
| mozilla | firefox | 0.8 |
| mozilla | firefox | 0.9 |
| mozilla | firefox | 0.9 |
| mozilla | firefox | 0.9.1 |
| mozilla | firefox | 0.9.2 |
| mozilla | firefox | 0.9.3 |
| mozilla | firefox | 0.10 |
| mozilla | firefox | 0.10.1 |
| mozilla | firefox | 1.0 |
| mozilla | firefox | 1.0.1 |
| mozilla | firefox | 1.0.2 |
| mozilla | firefox | 1.0.3 |
| mozilla | firefox | 1.0.4 |
| mozilla | firefox | 1.0.5 |
| mozilla | firefox | 1.0.6 |
| mozilla | firefox | 1.0.7 |
| mozilla | firefox | 1.0.8 |
| mozilla | firefox | 1.5 |
| mozilla | firefox | 1.5 |
| mozilla | firefox | 1.5 |
| mozilla | firefox | 1.5.0.1 |
| mozilla | firefox | 1.5.0.2 |
| mozilla | firefox | 1.5.0.3 |
| mozilla | firefox | 1.5.0.4 |
| mozilla | firefox | 1.5.0.5 |
| mozilla | firefox | 1.5.0.6 |
| netscape | navigator | 8.1 |
Check a specific version with /api/v1/cve/match.
References
- ftp://patches.sgi.com/support/free/security/advisories/20060901-01-P.asc
- http://lcamtuf.coredump.cx/ffoxdie.html
- http://lcamtuf.coredump.cx/ffoxdie3.html
- http://secunia.com/advisories/21513
- http://secunia.com/advisories/21906
- http://secunia.com/advisories/21915
- http://secunia.com/advisories/21916
- http://secunia.com/advisories/21939
- http://secunia.com/advisories/21940
- http://secunia.com/advisories/21949
- http://secunia.com/advisories/21950
- http://secunia.com/advisories/22001
- http://secunia.com/advisories/22025
- http://secunia.com/advisories/22036
- http://secunia.com/advisories/22055
- http://secunia.com/advisories/22056
- http://secunia.com/advisories/22066
- http://secunia.com/advisories/22074
- http://secunia.com/advisories/22088
- http://secunia.com/advisories/22195
- http://secunia.com/advisories/22210
- http://secunia.com/advisories/22274
- http://secunia.com/advisories/22391
- http://secunia.com/advisories/22422
- http://secunia.com/advisories/24711
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2006-4253