Oval Definition:oval:org.mitre.oval:def:1614
Revision Date:2011-02-21Version:6
Title:Mozilla CSS Letter-Spacing Heap Overflow Vulnerability
Description:Integer overflow in Mozilla Firefox and Thunderbird 1.x before 1.5.0.2 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0.1 allows remote attackers to execute arbitrary code via a large number in the CSS letter-spacing property that leads to a heap-based buffer overflow.
Family:windowsClass:vulnerability
Status:ACCEPTEDReference(s):CVE-2006-1730
Platform(s):Microsoft Windows 2000
Microsoft Windows Server 2003
Microsoft Windows XP
Product(s):mozilla
Definition Synopsis
  • Mozilla Firefox version 1.5 is installed and has NOT been patched with version 1.5.0.2
  • Mozilla Firefox version 1.5 is installed
  • AND Firefox version 1.5 or earlier is installed
  • AND NOT The version of Firefox.exe is greater than or equal to 1.8.20060.30804 (v1.5.0.2)
  • OR Mozilla Firefox version 1.5.0.1 is installed
  • Mozilla Firefox version 1.5.0.1 is installed
  • AND Firefox version 1.5.0.1 is installed
  • OR Mozilla Firefox version 1.0.7 or earlier is installed
  • Mozilla Firefox version 1.0.7 or earlier is installed
  • AND Firefox version 1.0.7 or earlier is installed
  • OR Mozilla Thunderbird version 1.5 is installed and has NOT been patched with version 1.5.0.2
  • Thunderbird version 1.5 or earlier is installed
  • AND Mozilla Thunderbird version 1.5 is installed
  • AND NOT The version of thunderbird.exe is greater than or equal to 1.8.20060.30803 (v1.5.0.2)
  • OR Mozilla Thunderbird version 1.0.7 or earlier is installed
  • Mozilla Thunderbird version 1.0.7 or earlier is installed
  • AND Mozilla Thunderbird version 1.0.7 or earlier is installed
  • OR SeaMonkey version 1.0 or earlier is installed
  • SeaMonkey version 1.0 or earlier is installed
  • AND SeaMonkey version 1.0 or earlier is installed
  • OR Mozilla Suite version 1.7.12 or earlier is installed
  • Mozilla Suite version 1.7.12 or earlier is installed
  • AND Mozilla Suite version 1.7.12 or earlier is installed
  • BACK