9.3
CVSSv2

CVE-2006-1726

Published: 14/04/2006 Updated: 18/10/2018
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Unspecified vulnerability in Firefox and Thunderbird 1.5 prior to 1.5.0.2, and SeaMonkey prior to 1.0.1, allows remote malicious users to bypass the js_ValueToFunctionObject check and execute arbitrary code via unknown vectors involving setTimeout and Firefox' ForEach method.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox 1.0.1

mozilla firefox 1.0.2

mozilla firefox 1.5.0.1

mozilla firefox 1.5

mozilla thunderbird 1.0.2

mozilla thunderbird 1.0.3

mozilla firefox 1.0.5

mozilla firefox 1.0.6

mozilla seamonkey 1.0

mozilla thunderbird 1.0.5

mozilla thunderbird 1.0.6

mozilla firefox 1.0

mozilla firefox 1.0.7

mozilla thunderbird 1.0

mozilla thunderbird 1.0.1

mozilla thunderbird 1.0.7

mozilla thunderbird 1.5

mozilla firefox 1.0.3

mozilla firefox 1.0.4

mozilla firefox preview_release

mozilla thunderbird 1.0.4

Vendor Advisories

Mozilla Foundation Security Advisory 2006-28 Security check of js_ValueToFunctionObject() can be circumvented Announced April 13, 2006 Reporter shutdown Impact Critical Products Firefox, SeaMonkey, Thunderbird Fixed in ...