peter bassill · operator
$ cve CVE-2006-3677 JSON

CVE-2006-3677 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 78.7% (pctl 100)

Patch early

A public exploit exists.

Description

Mozilla Firefox 1.5 before 1.5.0.5 and SeaMonkey before 1.0.3 allows remote attackers to execute arbitrary code by changing certain properties of the window navigator object (window.navigator) that are accessed when Java starts up, which causes a crash that leads to code execution.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS78.69% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-16
On CISA KEVno
Public exploityes
Published2006-07-27
Last modified2026-06-16

Affected (2)

VendorProduct
mozillafirefox
mozillaseamonkey

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD