CVE-2006-0298
published 2006-02-02CVE-2006-0298: The XML parser in Mozilla Firefox before 1.5.0.1 and SeaMonkey before 1.0 allows remote attackers to cause a denial of service (crash) and possibly read…
PriorityP414medium5.8CVSS 2.0
AVNACMAuNCPINAP
EPSS
2.71%
84.2th percentile
The XML parser in Mozilla Firefox before 1.5.0.1 and SeaMonkey before 1.0 allows remote attackers to cause a denial of service (crash) and possibly read sensitive data via unknown attack vectors that trigger an out-of-bounds read.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | < firefox 1.5.dfsg+1.5.0.1-1 (sid) | firefox 1.5.dfsg+1.5.0.1-1 (sid) |
| debian | thunderbird | < firefox 1.5.dfsg+1.5.0.1-1 (sid) | firefox 1.5.dfsg+1.5.0.1-1 (sid) |
| mozilla | firefox | — | — |
| mozilla | seamonkey | — | — |
| mozilla | thunderbird | >= 0 < 1.5.0.2-1 | 1.5.0.2-1 |
| mozilla | thunderbird | >= 0 < 1.5.0.2-1 | 1.5.0.2-1 |
| mozilla | thunderbird | >= 0 < 1.5.0.2-1 | 1.5.0.2-1 |
| mozilla | thunderbird | >= 0 < 1.5.0.2-1 | 1.5.0.2-1 |
CVSS provenance
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:P
osv5.8MEDIUM
vendor_debian5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-59jq-qmh2-r6c7: The XML parser in Mozilla Firefox before 1
ghsa_unreviewed·2022-05-01
CVE-2006-0298 [MEDIUM] CWE-20 GHSA-59jq-qmh2-r6c7: The XML parser in Mozilla Firefox before 1
The XML parser in Mozilla Firefox before 1.5.0.1 and SeaMonkey before 1.0 allows remote attackers to cause a denial of service (crash) and possibly read sensitive data via unknown attack vectors that trigger an out-of-bounds read.
OSV
CVE-2006-0298: The XML parser in Mozilla Firefox before 1
osv·2006-02-02·CVSS 5.8
CVE-2006-0298 [MEDIUM] CVE-2006-0298: The XML parser in Mozilla Firefox before 1
The XML parser in Mozilla Firefox before 1.5.0.1 and SeaMonkey before 1.0 allows remote attackers to cause a denial of service (crash) and possibly read sensitive data via unknown attack vectors that trigger an out-of-bounds read.
Debian
CVE-2006-0298: firefox - The XML parser in Mozilla Firefox before 1.5.0.1 and SeaMonkey before 1.0 allows...
vendor_debian·2006·CVSS 5.8
CVE-2006-0298 [MEDIUM] CVE-2006-0298: firefox - The XML parser in Mozilla Firefox before 1.5.0.1 and SeaMonkey before 1.0 allows...
The XML parser in Mozilla Firefox before 1.5.0.1 and SeaMonkey before 1.0 allows remote attackers to cause a denial of service (crash) and possibly read sensitive data via unknown attack vectors that trigger an out-of-bounds read.
Scope: local
sid: resolved (fixed in 1.5.dfsg+1.5.0.1-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/18700http://secunia.com/advisories/18704http://secunia.com/advisories/22065http://securitytracker.com/id?1015570http://www.mozilla.org/security/announce/2006/mfsa2006-07.htmlhttp://www.securityfocus.com/archive/1/446657/100/200/threadedhttp://www.securityfocus.com/bid/16476http://www.vupen.com/english/advisories/2006/0413http://www.vupen.com/english/advisories/2006/3749https://exchange.xforce.ibmcloud.com/vulnerabilities/24436https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A677http://secunia.com/advisories/18700http://secunia.com/advisories/18704http://secunia.com/advisories/22065http://securitytracker.com/id?1015570http://www.mozilla.org/security/announce/2006/mfsa2006-07.htmlhttp://www.securityfocus.com/archive/1/446657/100/200/threadedhttp://www.securityfocus.com/bid/16476http://www.vupen.com/english/advisories/2006/0413http://www.vupen.com/english/advisories/2006/3749https://exchange.xforce.ibmcloud.com/vulnerabilities/24436https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A677
2006-02-02
Published