CVE-2006-0749
Mozilla Firefox Tag Parsing Code Execution Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
nsHTMLContentSink.cpp in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors involving a "particular sequence of HTML tags" that leads to memory corruption.
This vulnerability allows attackers to execute arbitrary code on vulnerable installations of the Mozilla/Firefox web browser and Thunderbird e-mail client. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious e-mail.
The specific flaw exists within nsHTMLContentSink.cpp, during the parsing of HTML tags as they appear in a specific order. The flaw results in a memory corruption that leads to an attacker controlled function pointer dereference from the stack and eventually execution of arbitrary code.
Several security related problems have been discovered in Mozilla Thunderbird. This advisory addresses those issues.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2006-02-17 CVE Reserved
- 2006-04-14 CVE Published
- 2024-08-07 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-399: Resource Management Errors
CAPEC
References (61)
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Mozilla Search vendor "Mozilla" | Firefox Search vendor "Mozilla" for product "Firefox" | >= 1.0 <= 1.5 Search vendor "Mozilla" for product "Firefox" and version " >= 1.0 <= 1.5" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Mozilla Suite Search vendor "Mozilla" for product "Mozilla Suite" | < 1.7.13 Search vendor "Mozilla" for product "Mozilla Suite" and version " < 1.7.13" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Seamonkey Search vendor "Mozilla" for product "Seamonkey" | < 1.0 Search vendor "Mozilla" for product "Seamonkey" and version " < 1.0" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Thunderbird Search vendor "Mozilla" for product "Thunderbird" | >= 1.0 < 1.0.8 Search vendor "Mozilla" for product "Thunderbird" and version " >= 1.0 < 1.0.8" | - |
Affected
|