Mozilla Firefox 1.5 before 1.5.0.5 and SeaMonkey before 1.0.3 allows remote attackers to execute arbitrary code by changing certain properties of the window navigator object (window.navigator) that are accessed when Java starts up, which causes a crash that leads to code execution.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade linux-thunderbirdUpgrade linux-mozilla-develUpgrade mozillaUpgrade thunderbirdUpgrade linux-seamonkeyUpgrade firefoxUpgrade seamonkeyUpgrade linux-mozillaUpgrade linux-firefox-develUpgrade mozilla-thunderbirdUpgrade linux-firefox | Dec 10, 2025 | Jul 27, 2006 |
| Gentoo Linux | — | Upgrade www-client/seamonkey.Upgrade www-client/mozilla-firefox-bin.Upgrade www-client/mozilla-firefox. | Oct 30, 2017 | Jul 27, 2006 |
| Mfsa2006 45 | — | Upgrade to Mozilla Firefox version 1.5.0.5Upgrade to the latest version of Mozilla Firefox | Jul 25, 2006 | Jul 25, 2006 |
| Ubuntu | — | Upgrade firefox | Nov 8, 2024 | Jul 27, 2006 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub