CVE-2006-2779
Publication date 2 June 2006
Last updated 24 July 2024
Ubuntu priority
Mozilla Firefox and Thunderbird before 1.5.0.4 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) nested <option> tags in a select tag, (2) a DOMNodeRemoved mutation event, (3) "Content-implemented tree views," (4) BoxObjects, (5) the XBL implementation, (6) an iframe that attempts to remove itself, which leads to memory corruption.
Status
Package | Ubuntu Release | Status |
---|---|---|
firefox | ||
firefox-granparadiso | ||
lightning-sunbird | ||
midbrowser | ||
mozilla-thunderbird | ||
References
Related Ubuntu Security Notices (USN)
- USN-323-1
- mozilla vulnerabilities
- 26 July 2006
- USN-297-1
- Thunderbird vulnerabilities
- 14 June 2006
- USN-297-3
- Thunderbird vulnerabilities
- 26 July 2006
- USN-296-2
- Firefox vulnerabilities
- 25 July 2006
- USN-296-1
- firefox vulnerabilities
- 9 June 2006