Multiple integer overflows in the Javascript engine in Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 might allow remote attackers to execute arbitrary code via vectors involving (1) long strings in the toSource method of the Object, Array, and String objects; and (2) unspecified "string function arguments."
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2006-07-27 19:04
Updated : 2025-04-03 01:03
NVD link : CVE-2006-3806
Mitre link : CVE-2006-3806
CVE.ORG link : CVE-2006-3806
JSON object : View
Products Affected
mozilla
- thunderbird
- firefox
- seamonkey
CWE
CWE-189
Numeric Errors