FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2006-1726

This CVE name corresponds to:

Entered Topic
2006-04-16 mozilla -- multiple vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2006-1726
Phase Assigned(20060412)

Description

Unspecified vulnerability in Firefox and Thunderbird 1.5 before 1.5.0.2, and SeaMonkey before 1.0.1, allows remote attackers to bypass the js_ValueToFunctionObject check and execute arbitrary code via unknown vectors involving setTimeout and Firefox' ForEach method.

References

Source Reference
CONFIRM http://www.mozilla.org/security/announce/2006/mfsa2006-28.html
HP HPSBTU02118
HP SSRT061145
HP HPSBUX02153
HP SSRT061181
HP HPSBUX02156
HP SSRT061236
CERT TA06-107A
CERT-VN VU#968814
BID 17516
VUPEN ADV-2006-1356
VUPEN ADV-2006-3748
VUPEN ADV-2006-3749
VUPEN ADV-2008-0083
OVAL oval:org.mitre.oval:def:1968
SECTRACK 1015931
SECTRACK 1015932
SECTRACK 1015933
SECUNIA 19631
SECUNIA 19649
SECUNIA 22065
SECUNIA 22066
XF mozilla-valuetofunctionobject-sec-bypass(25825)