CVE-2006-3677
Last modified
CVE-2006-3677 is a vulnerability of currently unknown severity. Mozilla Firefox 1.5 before 1.5.0.5 and SeaMonkey before 1.0.3 allows remote attackers to execute arbitrary code by changing certain properties of the window navigator object (window.navigator) that are accessed when Java starts up, which causes a crash that leads to code execution.. EPSS estimates a 78.36% chance of exploitation in the next 30 days.
Description
Mozilla Firefox 1.5 before 1.5.0.5 and SeaMonkey before 1.0.3 allows remote attackers to execute arbitrary code by changing certain properties of the window navigator object (window.navigator) that are accessed when Java starts up, which causes a crash that leads to code execution.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox | 1.5 |
| Mozilla | Firefox | 1.5.0.1 |
| Mozilla | Firefox | 1.5.0.2 |
| Mozilla | Firefox | 1.5.0.3 |
| Mozilla | Firefox | 1.5.0.4 |
| Mozilla | Seamonkey | 1.0 |
| Mozilla | Seamonkey | 1.0.1 |
| Mozilla | Seamonkey | 1.0.2 |
References
- http://rhn.redhat.com/errata/RHSA-2006-0609.htmlVendor Advisory
- http://secunia.com/advisories/19873Patch, Vendor Advisory
- http://secunia.com/advisories/21216Patch, Vendor Advisory
- http://secunia.com/advisories/21229Patch, Vendor Advisory
- http://secunia.com/advisories/21243Vendor Advisory
- http://secunia.com/advisories/21246Vendor Advisory
- http://secunia.com/advisories/21262Vendor Advisory
- http://secunia.com/advisories/21269Vendor Advisory
- http://secunia.com/advisories/21270Vendor Advisory
- http://secunia.com/advisories/21336Vendor Advisory
- http://secunia.com/advisories/21343Vendor Advisory
- http://secunia.com/advisories/21361Vendor Advisory
- http://secunia.com/advisories/21529Vendor Advisory
- http://secunia.com/advisories/21532Vendor Advisory
- http://secunia.com/advisories/21631Vendor Advisory
- http://secunia.com/advisories/22066Vendor Advisory
- http://secunia.com/advisories/22210Vendor Advisory
- http://www.kb.cert.org/vuls/id/670060Third Party Advisory, US Government Resource
- http://www.redhat.com/support/errata/RHSA-2006-0594.htmlVendor Advisory
- http://www.redhat.com/support/errata/RHSA-2006-0608.htmlVendor Advisory
- http://www.redhat.com/support/errata/RHSA-2006-0610.htmlVendor Advisory
- http://www.redhat.com/support/errata/RHSA-2006-0611.htmlVendor Advisory
- http://www.us-cert.gov/cas/techalerts/TA06-208A.htmlUS Government Resource
- http://www.vupen.com/english/advisories/2006/2998Vendor Advisory
- http://www.vupen.com/english/advisories/2006/3748Vendor Advisory
- http://www.vupen.com/english/advisories/2008/0083Vendor Advisory
- http://www.zerodayinitiative.com/advisories/ZDI-06-025.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2006-0609.htmlVendor Advisory
- http://secunia.com/advisories/19873Patch, Vendor Advisory
- http://secunia.com/advisories/21216Patch, Vendor Advisory
- http://secunia.com/advisories/21229Patch, Vendor Advisory
- http://secunia.com/advisories/21243Vendor Advisory
- http://secunia.com/advisories/21246Vendor Advisory
- http://secunia.com/advisories/21262Vendor Advisory
- http://secunia.com/advisories/21269Vendor Advisory
- http://secunia.com/advisories/21270Vendor Advisory
- http://secunia.com/advisories/21336Vendor Advisory
- http://secunia.com/advisories/21343Vendor Advisory
- http://secunia.com/advisories/21361Vendor Advisory
- http://secunia.com/advisories/21529Vendor Advisory
- http://secunia.com/advisories/21532Vendor Advisory
- http://secunia.com/advisories/21631Vendor Advisory
- http://secunia.com/advisories/22066Vendor Advisory
- http://secunia.com/advisories/22210Vendor Advisory
- http://www.kb.cert.org/vuls/id/670060Third Party Advisory, US Government Resource
- http://www.redhat.com/support/errata/RHSA-2006-0594.htmlVendor Advisory
- http://www.redhat.com/support/errata/RHSA-2006-0608.htmlVendor Advisory
- http://www.redhat.com/support/errata/RHSA-2006-0610.htmlVendor Advisory
- http://www.redhat.com/support/errata/RHSA-2006-0611.htmlVendor Advisory
- http://www.us-cert.gov/cas/techalerts/TA06-208A.htmlUS Government Resource
- http://www.vupen.com/english/advisories/2006/2998Vendor Advisory
- http://www.vupen.com/english/advisories/2006/3748Vendor Advisory
- http://www.vupen.com/english/advisories/2008/0083Vendor Advisory
- http://www.zerodayinitiative.com/advisories/ZDI-06-025.htmlVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2006-3677?
How severe is CVE-2006-3677?
How do I fix CVE-2006-3677?
Are you affected by CVE-2006-3677?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
