CVE-2006-3807
EPSS 5.4%
描述
Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 allows remote attackers to execute arbitrary code via script that changes the standard Object() constructor to return a reference to a privileged object and calling "named JavaScript functions" that use the constructor.
如何修補 CVE-2006-3807
要修補 CVE-2006-3807,請將受影響套件升級到下列已修補版本。
- Debian/thunderbird—升級至 1.5.0.5-1 或更新版本
CVE-2006-3807 正在被利用嗎?
中等 — EPSS 為 5.4%,可持續追蹤但非最高優先。
受影響套件(1)
- from 0, < 1.5.0.5-1