{
    "id": "CVE-2006-4253",
    "published": "2006-08-21 20:04:00",
    "last_modified": "2026-06-16 22:28:43",
    "cvss_score": "7.6",
    "cvss_severity": "HIGH",
    "cvss_version": "2.0",
    "cvss_vector": "AV:N/AC:H/Au:N/C:C/I:C/A:C",
    "cwe": "CWE-264",
    "description": "Concurrency vulnerability in Mozilla Firefox 1.5.0.6 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via multiple Javascript timed events that load a deeply nested XML file, followed by redirecting the browser to another page, which leads to a concurrency failure that causes structures to be freed incorrectly, as demonstrated by (1) ffoxdie and (2) ffoxdie3.  NOTE: it has been reported that Netscape 8.1 and K-Meleon 1.0.1 are also affected by ffoxdie.  Mozilla confirmed to CVE that ffoxdie and ffoxdie3 trigger the same underlying vulnerability.  NOTE: it was later reported that Firefox 2.0 RC2 and 1.5.0.7 are also affected.",
    "epss_score": "0.15185",
    "epss_percentile": "0.96647",
    "kev": 0,
    "kev_due": null,
    "has_exploit": 1,
    "updated_at": "2026-09-30 18:17:05",
    "priority": {
        "rank": 2,
        "label": "Patch early",
        "why": "A public exploit exists."
    },
    "products": [
        {
            "vendor": "k-meleon_project",
            "product": "k-meleon"
        },
        {
            "vendor": "mozilla",
            "product": "firefox"
        },
        {
            "vendor": "netscape",
            "product": "navigator"
        }
    ],
    "kev_detail": null,
    "exploits": [
        {
            "source": "exploit-db",
            "ref_id": "28380",
            "title": "Mozilla Firefox 1.0.x - JavaScript Handler Race Condition Memory Corruption",
            "date": "2006-08-12",
            "url": "https://www.exploit-db.com/exploits/28380"
        }
    ],
    "refs_list": [
        "ftp://patches.sgi.com/support/free/security/advisories/20060901-01-P.asc",
        "http://lcamtuf.coredump.cx/ffoxdie.html",
        "http://lcamtuf.coredump.cx/ffoxdie3.html",
        "http://secunia.com/advisories/21513",
        "http://secunia.com/advisories/21906",
        "http://secunia.com/advisories/21915",
        "http://secunia.com/advisories/21916",
        "http://secunia.com/advisories/21939",
        "http://secunia.com/advisories/21940",
        "http://secunia.com/advisories/21949",
        "http://secunia.com/advisories/21950",
        "http://secunia.com/advisories/22001",
        "http://secunia.com/advisories/22025",
        "http://secunia.com/advisories/22036",
        "http://secunia.com/advisories/22055",
        "http://secunia.com/advisories/22056",
        "http://secunia.com/advisories/22066",
        "http://secunia.com/advisories/22074",
        "http://secunia.com/advisories/22088",
        "http://secunia.com/advisories/22195",
        "http://secunia.com/advisories/22210",
        "http://secunia.com/advisories/22274",
        "http://secunia.com/advisories/22391",
        "http://secunia.com/advisories/22422",
        "http://secunia.com/advisories/24711"
    ]
}