Mozilla Firefox 1.5 before 1.5.0.5 and SeaMonkey before 1.0.3 does not properly clear a JavaScript reference to a frame or window, which leaves a pointer to a deleted object that allows remote attackers to execute arbitrary native code.
CVSS Details
- CVSS 3.1 Base Score: 8.1
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade thunderbird | Jul 30, 2024 | Jul 27, 2006 |
| Freebsd | — | Upgrade linux-firefoxUpgrade mozillaUpgrade linux-thunderbirdUpgrade linux-mozillaUpgrade linux-firefox-develUpgrade linux-mozilla-develUpgrade linux-seamonkeyUpgrade firefoxUpgrade mozilla-thunderbirdUpgrade seamonkeyUpgrade thunderbird | Dec 10, 2025 | Jul 27, 2006 |
| Gentoo Linux | — | Upgrade www-client/seamonkey.Upgrade www-client/mozilla-firefox-bin.Upgrade www-client/mozilla-firefox. | Oct 30, 2017 | Jul 27, 2006 |
| Mfsa2006 44 | — | Upgrade to Mozilla Firefox version 1.5.0.5Upgrade to the latest version of Mozilla Firefox | Jul 25, 2006 | Jul 25, 2006 |
| Ubuntu | — | Upgrade firefox | Nov 8, 2024 | Jul 27, 2006 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub