CVE-2006-3677
Mozilla Firefox Javascript navigator Object Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
3Exploited in Wild
-Decision
Descriptions
Mozilla Firefox 1.5 before 1.5.0.5 and SeaMonkey before 1.0.3 allows remote attackers to execute arbitrary code by changing certain properties of the window navigator object (window.navigator) that are accessed when Java starts up, which causes a crash that leads to code execution.
Mozilla Firefox 1.5 anterior a 1.5.0.5 y SeaMonkey anterior a 1.0.3 permite a atacantes remotos ejecutar código de su elección cambiando ciertas propiedades del objeto de la ventana de navegación (window.navigator) que es accedido cuando comienza Java, lo cual provoca un caida que desemboca en una ejecución de código.
This vulnerability allows attackers to execute arbitrary code on vulnerable installations of the Mozilla Firefox web browser. User interaction is required to exploit this vulnerability in that the target must visit a malicious page.
The flaw exists when assigning specific values to the window.navigator object. A lack of checking on assignment causes user supplied data to be later used in the creation of other objects leading to eventual code execution.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2006-07-18 CVE Reserved
- 2006-07-25 First Exploit
- 2006-07-26 CVE Published
- 2024-06-16 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-16: Configuration
CAPEC
References (53)
URL | Tag | Source |
---|---|---|
http://securitytracker.com/id?1016586 | Vdb Entry | |
http://securitytracker.com/id?1016587 | Vdb Entry | |
http://www.kb.cert.org/vuls/id/670060 | Third Party Advisory | |
http://www.securityfocus.com/archive/1/441332/100/0/threaded | Mailing List | |
http://www.securityfocus.com/archive/1/441333/100/0/threaded | Mailing List | |
http://www.securityfocus.com/bid/19181 | Vdb Entry | |
http://www.us-cert.gov/cas/techalerts/TA06-208A.html | Third Party Advisory | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/27981 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/39998 | Vdb Entry | |
https://issues.rpath.com/browse/RPL-536 | X_refsource_confirm | |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10745 | Signature | |
http://www.mozilla.org/security/announce/mfsa2006-45.html |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/2082 | 2006-07-28 | |
https://www.exploit-db.com/exploits/9946 | 2006-07-25 | |
https://www.exploit-db.com/exploits/16300 | 2010-09-20 |
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/19873 | 2018-10-18 | |
http://secunia.com/advisories/21216 | 2018-10-18 | |
http://secunia.com/advisories/21229 | 2018-10-18 | |
http://www.securityfocus.com/bid/19192 | 2018-10-18 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Mozilla Search vendor "Mozilla" | Firefox Search vendor "Mozilla" for product "Firefox" | 1.5 Search vendor "Mozilla" for product "Firefox" and version "1.5" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Firefox Search vendor "Mozilla" for product "Firefox" | 1.5.0.1 Search vendor "Mozilla" for product "Firefox" and version "1.5.0.1" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Firefox Search vendor "Mozilla" for product "Firefox" | 1.5.0.2 Search vendor "Mozilla" for product "Firefox" and version "1.5.0.2" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Firefox Search vendor "Mozilla" for product "Firefox" | 1.5.0.3 Search vendor "Mozilla" for product "Firefox" and version "1.5.0.3" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Firefox Search vendor "Mozilla" for product "Firefox" | 1.5.0.4 Search vendor "Mozilla" for product "Firefox" and version "1.5.0.4" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Seamonkey Search vendor "Mozilla" for product "Seamonkey" | 1.0 Search vendor "Mozilla" for product "Seamonkey" and version "1.0" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Seamonkey Search vendor "Mozilla" for product "Seamonkey" | 1.0 Search vendor "Mozilla" for product "Seamonkey" and version "1.0" | dev |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Seamonkey Search vendor "Mozilla" for product "Seamonkey" | 1.0.1 Search vendor "Mozilla" for product "Seamonkey" and version "1.0.1" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Seamonkey Search vendor "Mozilla" for product "Seamonkey" | 1.0.2 Search vendor "Mozilla" for product "Seamonkey" and version "1.0.2" | - |
Affected
|