CVE-2006-0749

CWE-39923 documents8 sources
Severity
9.3CRITICAL
EPSS
36.4%
top 2.89%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 14
Latest updateMay 3

Description

nsHTMLContentSink.cpp in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors involving a "particular sequence of HTML tags" that leads to memory corruption.

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages5 packages

NVDmozilla/thunderbird1.01.0.8
NVDmozilla/mozilla_suite< 1.7.13
NVDmozilla/firefox1.01.5
Debianthunderbird< 1.5.0.2-1+3

🔴Vulnerability Details

3
GHSA
GHSA-pwcc-x4h8-g74h: nsHTMLContentSink2022-05-03
CVEList
CVE-2006-0749: nsHTMLContentSink2006-04-14
OSV
CVE-2006-0749: nsHTMLContentSink2006-04-14

📋Vendor Advisories

5
Ubuntu
Thunderbird vulnerabilities2006-05-03
Ubuntu
Mozilla vulnerabilities2006-04-28
Ubuntu
Firefox vulnerabilities2006-04-20
Red Hat
Firefox Tag Order Vulnerability2006-04-14
Debian
CVE-2006-0749: firefox - nsHTMLContentSink.cpp in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0....2006

💬Community

14
Bugzilla
Mozilla Thunderbird multiple vulnerabilities (CVE-2006-0749, CVE-2006-1724, CVE-2006-1730, CVE-2006-0292, et al.)2006-04-22
Bugzilla
multiple critical Firefox, Mozilla vulnerabilities (CVE-2006-0749, CVE-2006-1724, et al.)2006-04-17
Bugzilla
CVE-2006-0749 Mozilla Firefox Tag Order Vulnerability2006-04-13
Bugzilla
CVE-2006-0749 Mozilla Firefox Tag Order Vulnerability2006-04-13
Bugzilla
CVE-2006-0749 Mozilla Firefox Tag Order Vulnerability2006-04-13
CVE-2006-0749 (CRITICAL CVSS 9.3) | nsHTMLContentSink.cpp in Mozilla Fi | cvebase.io