Description
Mozilla Firefox 1.5.0.2, when designMode is enabled, allows remote attackers to cause a denial of service and possibly execute arbitrary code via certain Javascript that is not properly handled by the contentWindow.focus method in an iframe, which causes a reference to a deleted controller context object. NOTE: this was originally claimed to be a buffer overflow in (1) js320.dll and (2) xpcom_core.dll, but the vendor disputes this claim.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-1053-1 | New Mozilla packages fix arbitrary code execution |
Debian DSA |
DSA-1055-1 | New Mozilla Firefox packages fix arbitrary code execution |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-07T17:35:30.681Z
Reserved: 2006-04-25T00:00:00.000Z
Link: CVE-2006-1993
No data.
Status : Modified
Published: 2006-04-25T12:50:00.000
Modified: 2026-04-16T00:27:16.627
Link: CVE-2006-1993
No data.
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA