Return to CVE list

CVE-2006-4253

7.6
Critical

CVE-2006-4253

cve@mitre.org
Deferred

Description

Concurrency vulnerability in Mozilla Firefox 1.5.0.6 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via multiple Javascript timed events that load a deeply nested XML file, followed by redirecting the browser to another page, which leads to a concurrency failure that causes structures to be freed incorrectly, as demonstrated by (1) ffoxdie and (2) ffoxdie3. NOTE: it has been reported that Netscape 8.1 and K-Meleon 1.0.1 are also affected by ffoxdie. Mozilla confirmed to CVE that ffoxdie and ffoxdie3 trigger the same underlying vulnerability. NOTE: it was later reported that Firefox 2.0 RC2 and 1.5.0.7 are also affected.

References

af854a3a-2127-422b-91ae-364da2661108
http://lcamtuf.coredump.cx/ffoxdie.html
af854a3a-2127-422b-91ae-364da2661108
http://lcamtuf.coredump.cx/ffoxdie3.html
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/21513
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/21906
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/21915
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/21916
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/21939
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/21940
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/21949
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/21950
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/22001
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/22025
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/22036
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/22055
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/22056
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/22066
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/22074
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/22088
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/22195
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/22210
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/22274
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/22391
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/22422
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/24711
af854a3a-2127-422b-91ae-364da2661108
http://security.gentoo.org/glsa/glsa-200609-19.xml
af854a3a-2127-422b-91ae-364da2661108
http://security.gentoo.org/glsa/glsa-200610-01.xml
af854a3a-2127-422b-91ae-364da2661108
http://security.gentoo.org/glsa/glsa-200610-04.xml
af854a3a-2127-422b-91ae-364da2661108
http://securitytracker.com/id?1016846
af854a3a-2127-422b-91ae-364da2661108
http://securitytracker.com/id?1016847
af854a3a-2127-422b-91ae-364da2661108
http://securitytracker.com/id?1016848
af854a3a-2127-422b-91ae-364da2661108
http://www.pianetapc.it/view.php?id=770
af854a3a-2127-422b-91ae-364da2661108
http://www.securiteam.com/securitynews/5VP0M0AJFW.html
af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/bid/19488
af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/bid/19534
af854a3a-2127-422b-91ae-364da2661108
http://www.ubuntu.com/usn/usn-350-1
af854a3a-2127-422b-91ae-364da2661108
http://www.ubuntu.com/usn/usn-351-1
af854a3a-2127-422b-91ae-364da2661108
http://www.ubuntu.com/usn/usn-352-1
af854a3a-2127-422b-91ae-364da2661108
http://www.ubuntu.com/usn/usn-354-1
af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2006/3617
af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2006/3748
af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2007/1198
af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2008/0083
af854a3a-2127-422b-91ae-364da2661108
https://bugzilla.mozilla.org/show_bug.cgi?id=348514
af854a3a-2127-422b-91ae-364da2661108
https://issues.rpath.com/browse/RPL-640