PT-2006-1368 · Mozilla · Firefox+2
Martijn Wargers
·
Published
2006-02-02
·
Updated
2018-10-19
·
CVE-2006-0294
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Mozilla Firefox versions prior to 1.5.0.1
Thunderbird version 1.5
SeaMonkey versions prior to 1.0
Description
The issue allows remote attackers to execute arbitrary code by changing an element's style from position:relative to position:static, which causes Gecko to operate on freed memory.
Recommendations
For Mozilla Firefox versions prior to 1.5.0.1, update to version 1.5.0.1 or later.
For Thunderbird version 1.5, disable Javascript in mail to mitigate the risk.
For SeaMonkey versions prior to 1.0, update to version 1.0 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Firefox
Seamonkey
Thunderbird