5
CVSSv2

CVE-2006-5633

Published: 31/10/2006 Updated: 17/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Firefox 1.5.0.7 and 2.0, and Seamonkey 1.1b, allows remote malicious users to cause a denial of service (crash) by creating a range object using createRange, calling selectNode on a DocType node (DOCUMENT_TYPE_NODE), then calling createContextualFragment on the range, which triggers a null dereference. NOTE: the original Bugtraq post mentioned that code execution was possible, but followup analysis has shown that it is only a null dereference.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox 2.0

mozilla seamonkey 1.1

mozilla firefox 1.5.0.7

Exploits

<!-- ------------------------------------------------- Gotfault Security - Advisory #05 - 27/10/06 ------------------------------------------------- Software : Firefox Homepage : wwwmozillacom/ Vulnerable : 1507 and below, 20 Risk : Moderate Impact : Denial of Services (Code execution not verified) ----------------- ...