2.6
CVSSv2

CVE-2006-3731

Published: 21/07/2006 Updated: 17/10/2018
CVSS v2 Base Score: 2.6 | Impact Score: 2.9 | Exploitability Score: 4.9
VMScore: 231
Vector: AV:N/AC:H/Au:N/C:N/I:N/A:P

Vulnerability Summary

Mozilla Firefox 1.5.0.4 and previous versions allows remote user-assisted malicious users to cause a denial of service (crash) via a form with a multipart/form-data encoding and a user-uploaded file. NOTE: a third party has claimed that this issue might be related to the LiveHTTPHeaders extension.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox 1.5.0.2

mozilla firefox 1.5.0.3

mozilla firefox 1.5.0.4

mozilla firefox 1.5

mozilla firefox 1.5.0.1

Vendor Advisories

Debian Bug report logs - #379050 CVE-2006-3731: crash after upload with ENCTYPE="multipart/form-data" and reload Package: firefox; Maintainer for firefox is Maintainers of Mozilla-related packages <team+pkg-mozilla@trackerdebianorg>; Source for firefox is src:firefox (PTS, buildd, popcon) Reported by: Stefan Fritsch <sf ...