CVE-2006-0748Firefox vulnerability

CWE-39914 documents7 sources
Severity
9.3CRITICALNVD
EPSS
13.0%
top 5.89%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 14
Latest updateMay 3

Description

Mozilla Firefox and Thunderbird 1.x before 1.5.0.2 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0.1 allows remote attackers to execute arbitrary code via "an invalid and non-sensical ordering of table-related tags" that results in a negative array index.

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages6 packages

Debianmozilla/thunderbird< 1.5.0.2-1+3
NVDmozilla/firefox11 versions+10
NVDmozilla/thunderbird10 versions+9
debiandebian/firefox< firefox 1.5.dfsg+1.5.0.2-1 (sid)

🔴Vulnerability Details

2
GHSA
GHSA-hhhq-8f65-6q7x: Mozilla Firefox and Thunderbird 12022-05-03
OSV
CVE-2006-0748: Mozilla Firefox and Thunderbird 12006-04-14

📋Vendor Advisories

4
Ubuntu
Thunderbird vulnerabilities2006-05-03
Ubuntu
Mozilla vulnerabilities2006-04-28
Red Hat
security flaw2006-04-21
Debian
CVE-2006-0748: firefox - Mozilla Firefox and Thunderbird 1.x before 1.5.0.2 and 1.0.x before 1.0.8, Mozil...2006

💬Community

7
Bugzilla
CVE-2006-0748 security flaw2018-08-16
Bugzilla
CVE-2006-0748 Table Rebuilding Code Execution Vulnerability2006-04-13
Bugzilla
CVE-2006-0748 Table Rebuilding Code Execution Vulnerability2006-04-13
Bugzilla
CVE-2006-0748 Table Rebuilding Code Execution Vulnerability2006-04-13
Bugzilla
CVE-2006-0748 Table Rebuilding Code Execution Vulnerability2006-04-13