5.1
CVSSv2

CVE-2006-0295

Published: 02/02/2006 Updated: 19/10/2018
CVSS v2 Base Score: 5.1 | Impact Score: 6.4 | Exploitability Score: 4.9
VMScore: 525
Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P

Vulnerability Summary

Mozilla Firefox 1.5, Thunderbird 1.5 if Javascript is enabled in mail, and SeaMonkey prior to 1.0 might allow remote malicious users to execute arbitrary code via the QueryInterface method of the built-in Location and Navigator objects, which leads to memory corruption.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox 1.5

mozilla seamonkey 1.0

mozilla thunderbird 1.5

Vendor Advisories

Mozilla Foundation Security Advisory 2006-04 Memory corruption via QueryInterface on Location, Navigator objects Announced February 1, 2006 Reporter Georgi Guninski Impact Critical Products Firefox, SeaMonkey, Thunderbird ...

Exploits

## # This file is part of the Metasploit Framework and may be redistributed # according to the licenses defined in the Authors field below In the # case of an unknown or missing license, this file defaults to the same # license as the core Framework (dual GPLv2 and Artistic) The latest # version of the Framework can always be obtained from metasp ...
## # This file is part of the Metasploit Framework and may be redistributed # according to the licenses defined in the Authors field below In the # case of an unknown or missing license, this file defaults to the same # license as the core Framework (dual GPLv2 and Artistic) The latest # version of the Framework can always be obtained from metasp ...
## # $Id: firefox_queryinterfacerb 10394 2010-09-20 08:06:27Z jduck $ ## ## # This file is part of the Metasploit Framework and may be subject to # redistribution and commercial restrictions Please see the Metasploit # Framework web site for more information on licensing and terms of use # metasploitcom/framework/ ## require 'msf/core' ...