CVE-2006-0295 EXPLOIT
5.1
MEDIUM · CVSS 2.0 · EPSS 71.3% (pctl 99)
Patch early
A public exploit exists.
Description
Mozilla Firefox 1.5, Thunderbird 1.5 if Javascript is enabled in mail, and SeaMonkey before 1.0 might allow remote attackers to execute arbitrary code via the QueryInterface method of the built-in Location and Navigator objects, which leads to memory corruption.
Scoring
| CVSS | 5.1 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:H/Au:N/C:P/I:P/A:P |
| EPSS | 71.31% — more likely to be exploited than 99% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2006-02-02 |
| Last modified | 2026-06-16 |
Affected (3)
| Vendor | Product |
|---|---|
| mozilla | firefox |
| mozilla | seamonkey |
| mozilla | thunderbird |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Mozilla Firefox - location.QueryInterface() Code Execution (Metasploit) | 2010-09-20 |
| exploit-db | Mozilla Firefox 1.5 (OSX) - 'location.QueryInterface()' Code Execution (Metasploit) | 2006-02-08 |
| exploit-db | Mozilla Firefox 1.5 (Linux) - 'location.QueryInterface()' Code Execution (Metasploit) | 2006-02-07 |
References
- http://secunia.com/advisories/18700
- http://secunia.com/advisories/18704
- http://secunia.com/advisories/22065
- http://securitytracker.com/id?1015570
- http://www.kb.cert.org/vuls/id/759273
- http://www.mozilla.org/security/announce/2006/mfsa2006-04.html
- http://www.securityfocus.com/archive/1/446657/100/200/threaded
- http://www.securityfocus.com/bid/16476
- http://www.us-cert.gov/cas/techalerts/TA06-038A.html
- http://www.vupen.com/english/advisories/2006/0413
- http://www.vupen.com/english/advisories/2006/3749
- https://bugzilla.mozilla.org/show_bug.cgi?id=319296
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24433
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1562
- http://secunia.com/advisories/18700
- http://secunia.com/advisories/18704
- http://secunia.com/advisories/22065
- http://securitytracker.com/id?1015570
- http://www.kb.cert.org/vuls/id/759273
- http://www.mozilla.org/security/announce/2006/mfsa2006-04.html
→ the Explorer · watch your stack · NVD