CVE-2006-1742

16 documents8 sources
Severity
5.0MEDIUM
EPSS
14.0%
top 5.66%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 14
Latest updateMay 3

Description

The JavaScript engine in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 does not properly handle temporary variables that are not garbage collected, which might allow remote attackers to trigger operations on freed memory and cause memory corruption.

CVSS vector

AV:N/AC:L/C:N/I:P/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages5 packages

NVDmozilla/firefox1.0.7+8
NVDmozilla/thunderbird1.0.7+8
NVDmozilla/mozilla_suite1.7.12+5
Debianthunderbird< 1.5.0.2-1+3

🔴Vulnerability Details

3
GHSA
GHSA-7mq9-p447-2gr2: The JavaScript engine in Mozilla Firefox and Thunderbird 12022-05-03
CVEList
CVE-2006-1742: The JavaScript engine in Mozilla Firefox and Thunderbird 12006-04-14
OSV
CVE-2006-1742: The JavaScript engine in Mozilla Firefox and Thunderbird 12006-04-14

📋Vendor Advisories

5
Ubuntu
Thunderbird vulnerabilities2006-05-03
Ubuntu
Mozilla vulnerabilities2006-04-28
Ubuntu
Firefox vulnerabilities2006-04-20
Red Hat
security flaw2006-04-14
Debian
CVE-2006-1742: firefox - The JavaScript engine in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0....2006

💬Community

7
Bugzilla
CVE-2006-1742 security flaw2018-08-16
Bugzilla
CVE-2006-1742 JavaScript garbage-collection hazard audit2006-04-13
Bugzilla
CVE-2006-1742 JavaScript garbage-collection hazard audit2006-04-13
Bugzilla
CVE-2006-1742 JavaScript garbage-collection hazard audit2006-04-13
Bugzilla
CVE-2006-1742 JavaScript garbage-collection hazard audit2006-04-13