Multiple integer overflows in Mozilla Firefox 1.5, Thunderbird 1.5 if Javascript is enabled in mail, and SeaMonkey before 1.0 might allow remote attackers to execute arbitrary code via the (1) EscapeAttributeValue in jsxml.c for E4X, (2) nsSVGCairoSurface::Init in SVG, and (3) nsCanvasRenderingContext2D.cpp in Canvas.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: redhat

Published: 2006-02-02T22:00:00

Updated: 2018-10-19T14:57:01

Reserved: 2006-01-18T00:00:00


Link: CVE-2006-0297

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2006-02-02T22:02:00.000

Modified: 2018-10-19T15:44:06.533


Link: CVE-2006-0297

JSON object: View

cve-icon Redhat Information

No data.