7.5
CVSSv2

CVE-2006-0294

Published: 02/02/2006 Updated: 19/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 790
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Mozilla Firefox prior to 1.5.0.1, Thunderbird 1.5 if running Javascript in mail, and SeaMonkey prior to 1.0 allow remote malicious users to execute arbitrary code by changing an element's style from position:relative to position:static, which causes Gecko to operate on freed memory.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox 0.9

mozilla firefox 1.0

mozilla firefox 1.0.6

mozilla firefox 1.0.7

mozilla firefox 0.9.2

mozilla firefox 0.9.3

mozilla firefox 1.0.5

mozilla thunderbird 1.5

mozilla firefox 0.10

mozilla firefox 0.10.1

mozilla firefox 1.0.1

mozilla firefox 1.0.2

mozilla firefox 1.5

mozilla firefox 0.8

mozilla firefox 0.9.1

mozilla firefox 1.0.3

mozilla firefox 1.0.4

mozilla seamonkey 1.0

Vendor Advisories

Mozilla Foundation Security Advisory 2006-02 Changing position:relative to static corrupts memory Announced February 1, 2006 Reporter Martijn Wargers Impact Moderate Products Firefox, SeaMonkey, Thunderbird Fixed in ...