---
title: "CVE-2006-6504\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2006-6504?format=md
keywords: index, follow
---

# CVE-2006-6504

Publication date 20 December 2006

Last updated 17 July 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, and SeaMonkey
before 1.0.7 allows remote attackers to execute arbitrary code by appending
an SVG comment DOM node to another type of document, which triggers memory
corruption.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| firefox | 7.10 gutsy | Not affected |
| 7.04 feisty | Fixed 2.0.0.6+1-0ubuntu1 |
| 6.10 edgy | Fixed 2.0.0.6+0dfsg-0ubuntu0.6.10 |
| 6.06 LTS dapper | Fixed 1.5.dfsg+1.5.0.13~prepatch070731-0ubuntu1 |
| firefox-3.0 | 7.10 gutsy | Fixed 3.0~alpha7-0ubuntu6 |
| 7.04 feisty | Not in release |
| 6.10 edgy | Not in release |
| 6.06 LTS dapper | Not in release |
| iceape | 7.10 gutsy | Fixed 1.1.4-1ubuntu2 |
| 7.04 feisty | Not in release |
| 6.10 edgy | Not in release |
| 6.06 LTS dapper | Not in release |
| lightning-sunbird | 7.10 gutsy | Fixed 0.5-0ubuntu4 |
| 7.04 feisty | Not in release |
| 6.10 edgy | Not in release |
| 6.06 LTS dapper | Not in release |
| midbrowser | 7.10 gutsy | Fixed 0.1.6b-0ubuntu2 |
| 7.04 feisty | Not in release |
| 6.10 edgy | Not in release |
| 6.06 LTS dapper | Not in release |
| xulrunner | 7.10 gutsy | Fixed 1.8.0.10-3ubuntu1 |
| 7.04 feisty | Fixed 1.8.0.10-3ubuntu1 |
| 6.10 edgy | Ignored end of life, was needed |
| 6.06 LTS dapper | Not in release |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6504)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2006-6504)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2006-6504)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2006-6504)

### Related Ubuntu Security Notices (USN)

+ [USN-398-2](https://usn.ubuntu.com/USN-398-2)
+ Firefox vulnerabilities
+ 3 January 2007

+ [USN-398-1](https://usn.ubuntu.com/USN-398-1)
+ Firefox vulnerabilities
+ 3 January 2007

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2006-6504>
