---
title: "CVE-2006-0297\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2006-0297?format=md
keywords: index, follow
---

# CVE-2006-0297

Publication date 2 February 2006

Last updated 17 July 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

Multiple integer overflows in Mozilla Firefox 1.5, Thunderbird 1.5 if
Javascript is enabled in mail, and SeaMonkey before 1.0 might allow remote
attackers to execute arbitrary code via the (1) EscapeAttributeValue in
jsxml.c for E4X, (2) nsSVGCairoSurface::Init in SVG, and (3)
nsCanvasRenderingContext2D.cpp in Canvas.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| firefox | 7.04 feisty | Fixed 2.0.0.6+1-0ubuntu1 |
| 6.10 edgy | Fixed 2.0.0.6+0dfsg-0ubuntu0.6.10 |
| 6.06 LTS dapper | Fixed 1.5.dfsg+1.5.0.13~prepatch070731-0ubuntu1 |
| firefox-granparadiso | 7.04 feisty | Not in release |
| 6.10 edgy | Not in release |
| 6.06 LTS dapper | Not in release |
| lightning-sunbird | 7.04 feisty | Not in release |
| 6.10 edgy | Not in release |
| 6.06 LTS dapper | Not in release |
| midbrowser | 7.04 feisty | Not in release |
| 6.10 edgy | Not in release |
| 6.06 LTS dapper | Not in release |
| mozilla-thunderbird | 7.04 feisty | Fixed 1.5.0.13-0ubuntu0.7.04 |
| 6.10 edgy | Fixed 1.5.0.13-0ubuntu0.6.10 |
| 6.06 LTS dapper | Fixed 1.5.0.13-0ubuntu0.6.06 |
| xulrunner | 7.04 feisty | Fixed 1.8.0.5-4.2 |
| 6.10 edgy | Fixed 1.8.0.5-4.2 |
| 6.06 LTS dapper | Not in release |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0297)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2006-0297)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2006-0297)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2006-0297)

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2006-0297>
