
CVE-2006-6500
https://notcve.org/view.php?id=CVE-2006-6500
20 Dec 2006 — Heap-based buffer overflow in Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by setting the CSS cursor to certain images that cause an incorrect size calculation when converting to a Windows bitmap. Desbordamiento de búfer basado en pila en Mozilla Firefox 2.x anterior a 2.0.0.1, 1.5.x anterior a 1.5.0.9, Thunderbird anterior a 1.5.0.9, y SeaMonke... • http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2006-6499
https://notcve.org/view.php?id=CVE-2006-6499
20 Dec 2006 — The js_dtoa function in Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 overwrites memory instead of exiting when the floating point precision is reduced, which allows remote attackers to cause a denial of service via any plugins that reduce the precision. La función js_dtoa en Mozilla Firefox 2.x anterior a 2.0.0.1, 1.5.x anterior a 1.5.0.9, Thunderbird anterior a 1.5.0.9, y SeaMonkey anterior a 1.0.7 sobrescribe memoria en lugar de salir cua... • http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742 • CWE-835: Loop with Unreachable Exit Condition ('Infinite Loop') •

CVE-2006-6497
https://notcve.org/view.php?id=CVE-2006-6497
20 Dec 2006 — Multiple unspecified vulnerabilities in the layout engine for Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 allow remote attackers to cause a denial of service (memory corruption and crash) and possibly execute arbitrary code via unknown attack vectors. Múltiples vulnerabilidades no especificadas en el motor de diseño para Mozilla Firefox 2.x anterior a 2.0.0.1, 1.5.x anterior a 1.5.0.9, Thunderbird anterior a 1.5.0.9, y SeaMonkey anterior a... • ftp://patches.sgi.com/support/free/security/advisories/20061202-01-P.asc •

CVE-2006-6502
https://notcve.org/view.php?id=CVE-2006-6502
20 Dec 2006 — Use-after-free vulnerability in the LiveConnect bridge code for Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to cause a denial of service (crash) via unknown vectors. Vulnerabilidad de uso después de liberación (use-after-free) en el código puente LiveConnect para Mozilla Firefox 2.x anterior a 2.0.0.1, 1.5.x anterior a 1.5.0.9, Thunderbird anterior a 1.5.0.9, y SeaMonkey anterior a 1.0.7 permite a atacantes remotos ... • ftp://patches.sgi.com/support/free/security/advisories/20061202-01-P.asc •

CVE-2006-6506
https://notcve.org/view.php?id=CVE-2006-6506
20 Dec 2006 — The "Feed Preview" feature in Mozilla Firefox 2.0 before 2.0.0.1 sends the URL of the feed when requesting favicon.ico icons, which results in a privacy leak that might allow feed viewing services to determine browsing habits. La característica "Feed Preview" en Mozilla Firefox 2.0 anterior a 2.0.0.1 envía la URL del feed en la petición de iconos favicon.ico, lo cual implica una debilidad en la privacidad que puede permitir a los servicios que muestran feeds determinar hábitos de navegación. • http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742 •

CVE-2006-6503
https://notcve.org/view.php?id=CVE-2006-6503
20 Dec 2006 — Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to bypass cross-site scripting (XSS) protection by changing the src attribute of an IMG element to a javascript: URI. Mozilla Firefox 2.x anterior a 2.0.0.1, 1.5.x anterior a 1.5.0.9, Thunderbird anterior a 1.5.0.9, y SeaMonkey anterior a 1.0.7 permite a atacantes remotos evitar la protección de secuencias de comandos en sitios cruzados (XSS) cambiando el atributo src de u... • ftp://patches.sgi.com/support/free/security/advisories/20061202-01-P.asc • CWE-254: 7PK - Security Features •

CVE-2006-6504 – Mozilla Firefox SVG Processing Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2006-6504
19 Dec 2006 — Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to execute arbitrary code by appending an SVG comment DOM node to another type of document, which triggers memory corruption. Mozilla Firefox 2.x anterior a 2.0.0.1, 1.5.x anterior a 1.5.0.9, y SeaMonkey anterior a 1.0.7 permite a atacantes remotos ejecutar código de su elección añadiendo un nodo DOM con un comentario SVG a otro tipo de documento, lo cual desemboca en una corrupción de memoria. This ... • ftp://patches.sgi.com/support/free/security/advisories/20061202-01-P.asc • CWE-94: Improper Control of Generation of Code ('Code Injection') •

CVE-2006-6585
https://notcve.org/view.php?id=CVE-2006-6585
15 Dec 2006 — The Extensions manager in Mozilla Firefox 2.0 does not properly populate the list of local extensions, which allows attackers to construct an extension that hides itself by finding its name in the list and then calling RemoveElement, as demonstrated by the FFsniFF extension. NOTE: it was later reported that 3.0 is also affected. El manejador de extensiones de Mozilla Firefox 2.0 no rellena correctamente la lista de extensiones locales, lo caul permite a atacantes remotos construir una extensión que eso se o... • http://azurit.elbiahosting.sk/ffsniff/ffsniff-0.2.tar.gz •

CVE-2006-6077
https://notcve.org/view.php?id=CVE-2006-6077
24 Nov 2006 — The (1) Password Manager in Mozilla Firefox 2.0, and 1.5.0.8 and earlier; and the (2) Passcard Manager in Netscape 8.1.2 and possibly other versions, do not properly verify that an ACTION URL in a FORM element containing a password INPUT element matches the web site for which the user stored a password, which allows remote attackers to obtain passwords via a password INPUT element on a different web page located on the web site intended for this password. El (1) Password Manager en Mozilla Firefox 2.0, y 1.... • ftp://patches.sgi.com/support/free/security/advisories/20070202-01-P.asc •

CVE-2006-5463
https://notcve.org/view.php?id=CVE-2006-5463
08 Nov 2006 — Unspecified vulnerability in Mozilla Firefox before 1.5.0.8, Thunderbird before 1.5.0.8, and SeaMonkey before 1.0.6 allows remote attackers to execute arbitrary JavaScript bytecode via unspecified vectors involving modification of a Script object while it is executing. Vulnerabilidad sin especificar en el Mozilla Firefox en versiones anteriores a la 1.5.0.8, en el Thunderbird en versiones anteriores a la 1.5.0.8 y en el SeaMonkey en versiones anteriores a la 1.0.6, permite a atacantes remotos la ejecución d... • ftp://patches.sgi.com/support/free/security/advisories/20061101-01-P •