VDB
CVE-2006-0292
CVE-2006-0292
PUBLISHED
CVSS 7.5 HIGH
The Javascript interpreter (jsinterp.c) in Mozilla and Firefox before 1.5.1 does not properly dereference objects, which allows remote attackers to cause a denial of service (crash) or execute arbitrary code via unknown attack vectors related to garbage collection.
EPSS 4.58% · 90.9th percentile
Risk Scores
CVSS 2.0
7.5
EPSS Score
4.58%
90.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| mozilla | firefox | 1.0.2, 1.0.6, 1.0.7 |
| n/a | n/a | * |
| mozilla | mozilla | 1.4.1, 1.5, 1.4 |
Timeline
- Feb 2, 2006 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 19, 2022 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 26, 2023 EPSS Score
- Jul 18, 2023 EPSS Score
- Oct 31, 2023 EPSS Score
References
- MDKSA-2006:036 vendor-advisory
- 19902 third-party-advisory
- MDKSA-2006:037 vendor-advisory
- 19821 third-party-advisory
- 19862 third-party-advisory
- 18704 third-party-advisory
- SSRT061158 vendor-advisory
- RHSA-2006:0199 vendor-advisory
- 20051 third-party-advisory
- 18708 third-party-advisory
- DSA-1046 vendor-advisory
- GLSA-200604-12 vendor-advisory
- DSA-1051 vendor-advisory
- 18709 third-party-advisory
- ADV-2006-3749 vdb
- 18705 third-party-advisory
- 21033 third-party-advisory
- 102550 vendor-advisory
- MDKSA-2006:078 vendor-advisory
- FLSA:180036-1 vendor-advisory
…and 44 more