CVE-2006-5633
EPSS 6.9%
Description
Firefox 1.5.0.7 and 2.0, and Seamonkey 1.1b, allows remote attackers to cause a denial of service (crash) by creating a range object using createRange, calling selectNode on a DocType node (DOCUMENT_TYPE_NODE), then calling createContextualFragment on the range, which triggers a null dereference. NOTE: the original Bugtraq post mentioned that code execution was possible, but followup analysis has shown that it is only a null dereference.
How to fix CVE-2006-5633
To remediate CVE-2006-5633, upgrade the affected package to a fixed version below.
- Debian/firefox-esr—upgrade to 45.0esr-1 or later
Is CVE-2006-5633 being exploited?
Moderate — EPSS is 6.9%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- from 0, < 45.0esr-1