Executive Summary

Summary
Title Sun Alert 103011 Security Vulnerability in Mozilla 1.7 May Allow Arbitrary JavaScript Commands to be Run
Informations
Name SUN-103011 First vendor Publication 2007-07-24
Vendor Sun Last vendor Modification 2007-10-22
Severity (Vendor) N/A Revision N/A

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:L/Au:N/C:P/I:P/A:P)
Cvss Base Score 7.5 Attack Range Network
Cvss Impact Score 6.4 Attack Complexity Low
Cvss Expoit Score 10 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

Product: Mozilla v1.7

A remote code execution vulnerability in Mozilla 1.7 may allow a remote user who has created a web page visited by a local user using Mozilla, or who has sent a specially crafted e-mail read by a local user using Mozilla to execute arbitrary JavaScript commands with the privileges of that user.

This vulnerability is described in the following Mozilla advisory:

http://www.mozilla.org/security/announce/2006/mfsa2006-67.html

This issue is also described in the following documents:

CVE-2006-5463 at http://www.security-database.com/detail.php?cve=CVE-2006-5463

CERT VU#714496 at http://www.security-database.com/detail.php?vu=VU714496

CERT Technical Cyber Security Alert TA06-312A at http://www.us-cert.gov/cas/techalerts/TA06-312A.html

Avoidance: Patch
State: Resolved
First released: 24-Jul-2007

Original Source

Url : http://blogs.sun.com/security/entry/sun_alert_103011_security_vulnerability

OVAL Definitions

Definition Id: oval:org.mitre.oval:def:10357
 
Oval ID: oval:org.mitre.oval:def:10357
Title: Unspecified vulnerability in Mozilla Firefox before 1.5.0.8, Thunderbird before 1.5.0.8, and SeaMonkey before 1.0.6 allows remote attackers to execute arbitrary JavaScript bytecode via unspecified vectors involving modification of a Script object while it is executing.
Description: Unspecified vulnerability in Mozilla Firefox before 1.5.0.8, Thunderbird before 1.5.0.8, and SeaMonkey before 1.0.6 allows remote attackers to execute arbitrary JavaScript bytecode via unspecified vectors involving modification of a Script object while it is executing.
Family: unix Class: vulnerability
Reference(s): CVE-2006-5463
Version: 5
Platform(s): Red Hat Enterprise Linux 3
CentOS Linux 3
Red Hat Enterprise Linux 4
CentOS Linux 4
Oracle Linux 4
Product(s):
Definition Synopsis:

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 10
Application 6
Application 13

OpenVAS Exploits

Date Description
2008-09-24 Name : Gentoo Security Advisory GLSA 200612-06 (mozilla-thunderbird)
File : nvt/glsa_200612_06.nasl
2008-09-24 Name : Gentoo Security Advisory GLSA 200612-07 (mozilla-firefox)
File : nvt/glsa_200612_07.nasl
2008-09-24 Name : Gentoo Security Advisory GLSA 200612-08 (seamonkey)
File : nvt/glsa_200612_08.nasl
2008-01-17 Name : Debian Security Advisory DSA 1224-1 (mozilla)
File : nvt/deb_1224_1.nasl
2008-01-17 Name : Debian Security Advisory DSA 1225-1 (mozilla-firefox)
File : nvt/deb_1225_1.nasl
2008-01-17 Name : Debian Security Advisory DSA 1225-2 (mozilla-firefox)
File : nvt/deb_1225_2.nasl
2008-01-17 Name : Debian Security Advisory DSA 1227-1 (mozilla-thunderbird)
File : nvt/deb_1227_1.nasl

Open Source Vulnerability Database (OSVDB)

Id Description
30300 Mozilla Multiple Products Script Object Modification Arbitrary Javascript Byt...

Nessus® Vulnerability Scanner

Date Description
2013-07-12 Name : The remote Oracle Linux host is missing a security update.
File : oraclelinux_ELSA-2006-0735.nasl - Type : ACT_GATHER_INFO
2013-07-12 Name : The remote Oracle Linux host is missing a security update.
File : oraclelinux_ELSA-2006-0734.nasl - Type : ACT_GATHER_INFO
2013-07-12 Name : The remote Oracle Linux host is missing a security update.
File : oraclelinux_ELSA-2006-0733.nasl - Type : ACT_GATHER_INFO
2009-04-23 Name : The remote CentOS host is missing one or more security updates.
File : centos_RHSA-2006-0734.nasl - Type : ACT_GATHER_INFO
2009-04-23 Name : The remote CentOS host is missing a security update.
File : centos_RHSA-2006-0733.nasl - Type : ACT_GATHER_INFO
2009-04-23 Name : The remote CentOS host is missing a security update.
File : centos_RHSA-2006-0735.nasl - Type : ACT_GATHER_INFO
2007-12-13 Name : The remote SuSE 10 host is missing a security-related patch.
File : suse_MozillaFirefox-2258.nasl - Type : ACT_GATHER_INFO
2007-11-10 Name : The remote Ubuntu host is missing one or more security-related patches.
File : ubuntu_USN-382-1.nasl - Type : ACT_GATHER_INFO
2007-11-10 Name : The remote Ubuntu host is missing one or more security-related patches.
File : ubuntu_USN-381-1.nasl - Type : ACT_GATHER_INFO
2007-10-17 Name : The remote openSUSE host is missing a security update.
File : suse_MozillaFirefox-2251.nasl - Type : ACT_GATHER_INFO
2007-10-17 Name : The remote openSUSE host is missing a security update.
File : suse_MozillaThunderbird-2252.nasl - Type : ACT_GATHER_INFO
2007-10-17 Name : The remote openSUSE host is missing a security update.
File : suse_seamonkey-2250.nasl - Type : ACT_GATHER_INFO
2007-02-18 Name : The remote host is missing Sun Security Patch number 120671-08
File : solaris8_120671.nasl - Type : ACT_GATHER_INFO
2007-02-18 Name : The remote host is missing Sun Security Patch number 120671-08
File : solaris9_120671.nasl - Type : ACT_GATHER_INFO
2007-02-18 Name : The remote Mandrake Linux host is missing one or more security updates.
File : mandrake_MDKSA-2006-206.nasl - Type : ACT_GATHER_INFO
2007-02-18 Name : The remote Mandrake Linux host is missing one or more security updates.
File : mandrake_MDKSA-2006-205.nasl - Type : ACT_GATHER_INFO
2007-01-17 Name : The remote Fedora Core host is missing a security update.
File : fedora_2006-1194.nasl - Type : ACT_GATHER_INFO
2007-01-17 Name : The remote Fedora Core host is missing a security update.
File : fedora_2006-1192.nasl - Type : ACT_GATHER_INFO
2007-01-17 Name : The remote Fedora Core host is missing one or more security updates.
File : fedora_2006-1191.nasl - Type : ACT_GATHER_INFO
2007-01-17 Name : The remote Fedora Core host is missing a security update.
File : fedora_2006-1199.nasl - Type : ACT_GATHER_INFO
2006-12-14 Name : The remote Gentoo host is missing one or more security-related patches.
File : gentoo_GLSA-200612-08.nasl - Type : ACT_GATHER_INFO
2006-12-14 Name : The remote Gentoo host is missing one or more security-related patches.
File : gentoo_GLSA-200612-07.nasl - Type : ACT_GATHER_INFO
2006-12-14 Name : The remote Gentoo host is missing one or more security-related patches.
File : gentoo_GLSA-200612-06.nasl - Type : ACT_GATHER_INFO
2006-12-06 Name : The remote host is missing Sun Security Patch number 120672-08
File : solaris9_x86_120672.nasl - Type : ACT_GATHER_INFO
2006-12-06 Name : The remote host is missing Sun Security Patch number 120672-08
File : solaris8_x86_120672.nasl - Type : ACT_GATHER_INFO
2006-12-04 Name : The remote Debian host is missing a security-related update.
File : debian_DSA-1227.nasl - Type : ACT_GATHER_INFO
2006-12-04 Name : The remote Debian host is missing a security-related update.
File : debian_DSA-1224.nasl - Type : ACT_GATHER_INFO
2006-12-04 Name : The remote Debian host is missing a security-related update.
File : debian_DSA-1225.nasl - Type : ACT_GATHER_INFO
2006-11-20 Name : The remote Red Hat host is missing a security update.
File : redhat-RHSA-2006-0735.nasl - Type : ACT_GATHER_INFO
2006-11-20 Name : The remote Red Hat host is missing one or more security updates.
File : redhat-RHSA-2006-0734.nasl - Type : ACT_GATHER_INFO
2006-11-20 Name : The remote Red Hat host is missing a security update.
File : redhat-RHSA-2006-0733.nasl - Type : ACT_GATHER_INFO
2006-11-08 Name : A web browser on the remote host is prone to multiple flaws.
File : seamonkey_106.nasl - Type : ACT_GATHER_INFO
2006-11-08 Name : The remote Windows host contains a mail client that is affected by multiple v...
File : mozilla_thunderbird_1508.nasl - Type : ACT_GATHER_INFO
2006-11-08 Name : The remote Windows host contains a web browser that is affected by multiple v...
File : mozilla_firefox_1508.nasl - Type : ACT_GATHER_INFO
2006-11-06 Name : The remote host is missing Sun Security Patch number 119116-35
File : solaris10_x86_119116.nasl - Type : ACT_GATHER_INFO
2006-11-06 Name : The remote host is missing Sun Security Patch number 119115-36
File : solaris10_119115.nasl - Type : ACT_GATHER_INFO

Alert History

If you want to see full details history, please login or register.
0
Date Informations
2016-04-26 18:14:39
  • Multiple Updates