CVE-2006-3803
Summary
| CVE | CVE-2006-3803 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-07-27 19:04:00 UTC |
| Updated | 2018-10-17 21:30:00 UTC |
| Description | Race condition in the JavaScript garbage collection in Mozilla Firefox 1.5 before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 might allow remote attackers to execute arbitrary code by causing the garbage collector to delete a temporary variable while it is still being used during the creation of a new Function object. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Mozilla | Firefox | 1.5 | All | All | All |
| Application | Mozilla | Firefox | 1.5.0.1 | All | All | All |
| Application | Mozilla | Firefox | 1.5.0.2 | All | All | All |
| Application | Mozilla | Firefox | 1.5.0.3 | All | All | All |
| Application | Mozilla | Firefox | 1.5.0.4 | All | All | All |
| Application | Mozilla | Firefox | 1.5 | All | All | All |
| Application | Mozilla | Firefox | 1.5.0.1 | All | All | All |
| Application | Mozilla | Firefox | 1.5.0.2 | All | All | All |
| Application | Mozilla | Firefox | 1.5.0.3 | All | All | All |
| Application | Mozilla | Firefox | 1.5.0.4 | All | All | All |
| Application | Mozilla | Seamonkey | 1.0 | All | All | All |
| Application | Mozilla | Seamonkey | 1.0 | All | dev | All |
| Application | Mozilla | Seamonkey | 1.0.1 | All | All | All |
| Application | Mozilla | Seamonkey | 1.0.2 | All | All | All |
| Application | Mozilla | Seamonkey | 1.0 | All | All | All |
| Application | Mozilla | Seamonkey | 1.0 | All | dev | All |
| Application | Mozilla | Seamonkey | 1.0.1 | All | All | All |
| Application | Mozilla | Seamonkey | 1.0.2 | All | All | All |
| Application | Mozilla | Thunderbird | 1.5 | All | All | All |
| Application | Mozilla | Thunderbird | 1.5.0.2 | All | All | All |
| Application | Mozilla | Thunderbird | 1.5.0.4 | All | All | All |
| Application | Mozilla | Thunderbird | 1.5 | All | All | All |
| Application | Mozilla | Thunderbird | 1.5.0.2 | All | All | All |
| Application | Mozilla | Thunderbird | 1.5.0.4 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| issues.rpath.com/browse/RPL-537 | CONFIRM | issues.rpath.com | |
| rhn.redhat.com | Red Hat Support | REDHAT | rhn.redhat.com | |
| Mozilla Firefox Multiple Vulnerabilities - Advisories - Secunia | SECUNIA | secunia.com | Patch, Vendor Advisory |
| USN-329-1: Thunderbird vulnerabilities | Ubuntu security notices | UBUNTU | usn.ubuntu.com | |
| usn/usn-350-1 - Ubuntu: Linux for human beings | UBUNTU | www.ubuntu.com | |
| MFSA 2006-48: JavaScript new Function race condition | CONFIRM | www.mozilla.org | |
| SecurityFocus | HP | www.securityfocus.com | |
| Mozilla Thunderbird Multiple Vulnerabilities - Advisories - Secunia | SECUNIA | secunia.com | Patch, Vendor Advisory |
| [#RPL-536] update firefox to 1.5.0.5 for security issues - rPath JIRA | CONFIRM | issues.rpath.com | |
| Repository / Oval Repository | OVAL | oval.cisecurity.org | |
| HP-UX update for firefox - Advisories - Secunia | SECUNIA | secunia.com | |
| SecurityFocus | HP | www.securityfocus.com | |
| SecurityTracker.com Archives - Mozilla Seamonkey Multiple Bugs Let Remote Users Execute Arbitrary Code | SECTRACK | securitytracker.com | |
| Gentoo update for seamonkey - Advisories - Secunia | SECUNIA | secunia.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| Mozilla SeaMonkey Multiple Vulnerabilities - Advisories - Secunia | SECUNIA | secunia.com | Patch, Vendor Advisory |
| Mozilla Multiple Products Remote Vulnerabilities | BID | www.securityfocus.com | Patch |
| US-CERT Technical Cyber Security Alert TA06-208A -- Mozilla Products Contain Multiple Vulnerabilities | CERT | www.us-cert.gov | US Government Resource |
| rhn.redhat.com | Red Hat Support | REDHAT | www.redhat.com | |
| Ubuntu update for mozilla-thunderbird - Advisories - Secunia | SECUNIA | secunia.com | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| Advisories - Mandriva Linux | MANDRIVA | www.mandriva.com | |
| SUSE update for MozillaFirefox, MozillaThunderbird, and Seamonkey - Advisories - Secunia | SECUNIA | secunia.com | |
| usn/usn-354-1 - Ubuntu: Linux for human beings | UBUNTU | www.ubuntu.com | |
| Red Hat update for seamonkey - Advisories - Secunia | SECUNIA | secunia.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| Ubuntu update for firefox - Advisories - Secunia | SECUNIA | secunia.com | |
| Ubuntu update for firefox - Advisories - Secunia | SECUNIA | secunia.com | |
| rPath update for firefox - Advisories - Secunia | SECUNIA | secunia.com | Patch, Vendor Advisory |
| Mandriva update for mozilla-firefox - Advisories - Secunia | SECUNIA | secunia.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| Gentoo update for mozilla-firefox - Advisories - Secunia | SECUNIA | secunia.com | |
| rhn.redhat.com | Red Hat Support | REDHAT | www.redhat.com | |
| Red Hat update for seamonkey - Advisories - Secunia | SECUNIA | secunia.com | |
| rhn.redhat.com | Red Hat Support | REDHAT | www.redhat.com | |
| Mandriva update for mozilla-thunderbird - Advisories - Secunia | SECUNIA | secunia.com | |
| HP-UX update for thunderbird - Advisories - Secunia | SECUNIA | secunia.com | |
| SGI Advanced Linux Environment Multiple Updates - Advisories - Secunia | SECUNIA | secunia.com | |
| Gentoo Linux Documentation -- Mozilla SeaMonkey: Multiple vulnerabilities | GENTOO | security.gentoo.org | |
| rPath update for thunderbird - Advisories - Secunia | SECUNIA | secunia.com | |
| 20060703-01-P | SGI | patches.sgi.com | |
| Security Announcement | SUSE | www.novell.com | |
| Advisories - Mandriva Linux | MANDRIVA | www.mandriva.com | |
| Advisories - Mandriva Linux | MANDRIVA | www.mandriva.com | |
| Gentoo Linux Documentation -- Mozilla Thunderbird: Multiple vulnerabilities | GENTOO | security.gentoo.org | |
| Gentoo update for mozilla-thunderbird - Advisories - Secunia | SECUNIA | secunia.com | |
| SecurityTracker.com Archives - Mozilla Firefox Multiple Bugs Let Remote Users Execute Arbitrary Code | SECTRACK | securitytracker.com | |
| Red Hat update for seamonkey - Advisories - Secunia | SECUNIA | secunia.com | |
| USN-327-1: firefox vulnerabilities | Ubuntu security notices | UBUNTU | usn.ubuntu.com | |
| rhn.redhat.com | Red Hat Support | REDHAT | www.redhat.com | |
| Gentoo Linux Documentation -- Mozilla Firefox: Multiple vulnerabilities | GENTOO | www.gentoo.org | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| Red Hat update for thunderbird - Advisories - Secunia | SECUNIA | secunia.com | |
| US-CERT Vulnerability Note VU#265964 | CERT-VN | www.kb.cert.org | Third Party Advisory, US Government Resource |
| Red Hat update for firefox - Advisories - Secunia | SECUNIA | secunia.com | |
| Ubuntu update for thunderbird - Advisories - Secunia | SECUNIA | secunia.com | |
| SecurityTracker.com Archives - Mozilla Thunderbird Multiple Bugs Let Remote Users Execute Arbitrary Code | SECTRACK | securitytracker.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.