VDB
VAR-200607-0664
VAR-200607-0664
PUBLISHED
Mozilla Firefox 1.5 before 1.5.0.5 and SeaMonkey before 1.0.3 allows remote attackers to execute arbitrary code by changing certain properties of the window navigator object (window.navigator) that are accessed when Java starts up, which causes a crash that leads to code execution.
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
Timeline
- Jul 26, 2006 CVE Published
- Sep 20, 2010 PoC Published
- May 29, 2018 PoC Published
- Feb 6, 2025 PoC Published
- Feb 23, 2025 PoC Published
- Sep 9, 2025 PoC Published
- Apr 15, 2026 Distribution Patch
- Apr 15, 2026 Security Advisory
- Apr 15, 2026 Security Advisory
References
- 20060726 ZDI-06-025: Mozilla Firefox Javascript navigator Object Vulnerability mailing-list
- MDKSA-2006:145 vendor-advisory
- ADV-2006-3748 vdb
- iphone-mobilesafari-dos(39998) vdb
- mozilla-javascript-navigator-code-excecution(27981) vdb
- TA06-208A third-party-advisory
- 20060727 rPSA-2006-0137-1 firefox mailing-list
- 21529 third-party-advisory
- RHSA-2006:0610 vendor-advisory
- RHSA-2006:0609 vendor-advisory
- http://www.mozilla.org/security/announce/2006/mfsa2006-45.html url
- 21270 third-party-advisory
- ADV-2008-0083 vdb
- 21361 third-party-advisory
- 21246 third-party-advisory
- SUSE-SA:2006:048 vendor-advisory
- https://issues.rpath.com/browse/RPL-536 url
- 21269 third-party-advisory
- MDKSA-2006:143 vendor-advisory
- 19192 vdb
…and 27 more