CVE-2006-6499

high

Description

The js_dtoa function in Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 overwrites memory instead of exiting when the floating point precision is reduced, which allows remote attackers to cause a denial of service via any plugins that reduce the precision.

References

http://www.ubuntu.com/usn/usn-400-1

http://www.ubuntu.com/usn/usn-398-2

http://www.ubuntu.com/usn/usn-398-1

http://www.mozilla.org/security/announce/2006/mfsa2006-68.html

http://www.kb.cert.org/vuls/id/427972

http://www.gentoo.org/security/en/glsa/glsa-200701-04.xml

http://www.debian.org/security/2007/dsa-1265

http://www.debian.org/security/2007/dsa-1258

http://www.debian.org/security/2007/dsa-1253

Details

Source: Mitre, NVD

Published: 2006-12-20

Updated: 2023-12-22

Risk Information

CVSS v2

Base Score: 4.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:N/I:N/A:P

Severity: Medium

CVSS v3

Base Score: 7.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Severity: High