CVE-2006-3677
Summary
| CVE | CVE-2006-3677 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-07-27 19:04:00 UTC |
| Updated | 2018-10-18 16:48:00 UTC |
| Description | Mozilla Firefox 1.5 before 1.5.0.5 and SeaMonkey before 1.0.3 allows remote attackers to execute arbitrary code by changing certain properties of the window navigator object (window.navigator) that are accessed when Java starts up, which causes a crash that leads to code execution. |
Risk And Classification
Problem Types: CWE-16
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Mozilla | Firefox | 1.5 | All | All | All |
| Application | Mozilla | Firefox | 1.5.0.1 | All | All | All |
| Application | Mozilla | Firefox | 1.5.0.2 | All | All | All |
| Application | Mozilla | Firefox | 1.5.0.3 | All | All | All |
| Application | Mozilla | Firefox | 1.5.0.4 | All | All | All |
| Application | Mozilla | Firefox | 1.5 | All | All | All |
| Application | Mozilla | Firefox | 1.5.0.1 | All | All | All |
| Application | Mozilla | Firefox | 1.5.0.2 | All | All | All |
| Application | Mozilla | Firefox | 1.5.0.3 | All | All | All |
| Application | Mozilla | Firefox | 1.5.0.4 | All | All | All |
| Application | Mozilla | Seamonkey | 1.0 | All | All | All |
| Application | Mozilla | Seamonkey | 1.0 | All | dev | All |
| Application | Mozilla | Seamonkey | 1.0.1 | All | All | All |
| Application | Mozilla | Seamonkey | 1.0.2 | All | All | All |
| Application | Mozilla | Seamonkey | 1.0 | All | All | All |
| Application | Mozilla | Seamonkey | 1.0 | All | dev | All |
| Application | Mozilla | Seamonkey | 1.0.1 | All | All | All |
| Application | Mozilla | Seamonkey | 1.0.2 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| ZDI-06-025 | Zero Day Initiative | MISC | www.zerodayinitiative.com | Vendor Advisory |
| rhn.redhat.com | Red Hat Support | REDHAT | rhn.redhat.com | Vendor Advisory |
| Mozilla Firefox Multiple Vulnerabilities - Advisories - Secunia | SECUNIA | secunia.com | Patch, Vendor Advisory |
| SecurityFocus | HP | www.securityfocus.com | |
| [#RPL-536] update firefox to 1.5.0.5 for security issues - rPath JIRA | CONFIRM | issues.rpath.com | |
| US-CERT Vulnerability Note VU#670060 | CERT-VN | www.kb.cert.org | Third Party Advisory, US Government Resource |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| HP-UX update for firefox - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| SecurityTracker.com Archives - Mozilla Seamonkey Multiple Bugs Let Remote Users Execute Arbitrary Code | SECTRACK | securitytracker.com | |
| Gentoo update for seamonkey - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | Vendor Advisory |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| Mozilla SeaMonkey Multiple Vulnerabilities - Advisories - Secunia | SECUNIA | secunia.com | Patch, Vendor Advisory |
| Mozilla Multiple Products Remote Vulnerabilities | BID | www.securityfocus.com | |
| US-CERT Technical Cyber Security Alert TA06-208A -- Mozilla Products Contain Multiple Vulnerabilities | CERT | www.us-cert.gov | US Government Resource |
| rhn.redhat.com | Red Hat Support | REDHAT | www.redhat.com | Vendor Advisory |
| Advisories - Mandriva Linux | MANDRIVA | www.mandriva.com | |
| SUSE update for MozillaFirefox, MozillaThunderbird, and Seamonkey - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| usn/usn-354-1 - Ubuntu: Linux for human beings | UBUNTU | www.ubuntu.com | |
| Red Hat update for seamonkey - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | Vendor Advisory |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| Repository / Oval Repository | OVAL | oval.cisecurity.org | |
| Ubuntu update for firefox - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| Ubuntu update for firefox - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| rPath update for firefox - Advisories - Secunia | SECUNIA | secunia.com | Patch, Vendor Advisory |
| Mandriva update for mozilla-firefox - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | Vendor Advisory |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| Gentoo update for mozilla-firefox - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| MFSA 2006-45: Javascript navigator Object Vulnerability | CONFIRM | www.mozilla.org | Vendor Advisory |
| rhn.redhat.com | Red Hat Support | REDHAT | www.redhat.com | Vendor Advisory |
| Red Hat update for seamonkey - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| Mozilla Firefox Javascript Navigator Object Remote Code Execution Vulnerability | BID | www.securityfocus.com | Patch |
| rhn.redhat.com | Red Hat Support | REDHAT | www.redhat.com | Vendor Advisory |
| SGI Advanced Linux Environment Multiple Updates - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| Gentoo Linux Documentation -- Mozilla SeaMonkey: Multiple vulnerabilities | GENTOO | security.gentoo.org | |
| 20060703-01-P | SGI | patches.sgi.com | |
| Security Announcement | SUSE | www.novell.com | |
| Advisories - Mandriva Linux | MANDRIVA | www.mandriva.com | |
| SecurityTracker.com Archives - Mozilla Firefox Multiple Bugs Let Remote Users Execute Arbitrary Code | SECTRACK | securitytracker.com | |
| Red Hat update for seamonkey - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| USN-327-1: firefox vulnerabilities | Ubuntu security notices | UBUNTU | usn.ubuntu.com | |
| rhn.redhat.com | Red Hat Support | REDHAT | www.redhat.com | Vendor Advisory |
| Gentoo Linux Documentation -- Mozilla Firefox: Multiple vulnerabilities | GENTOO | www.gentoo.org | |
| Red Hat update for thunderbird - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| Red Hat update for firefox - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.