CVE-2006-1993
Publication date 25 April 2006
Last updated 17 July 2025
Ubuntu priority
Description
Mozilla Firefox 1.5.0.2, when designMode is enabled, allows remote attackers to cause a denial of service and possibly execute arbitrary code via certain Javascript that is not properly handled by the contentWindow.focus method in an iframe, which causes a reference to a deleted controller context object. NOTE: this was originally claimed to be a buffer overflow in (1) js320.dll and (2) xpcom_core.dll, but the vendor disputes this claim.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| firefox | ||
| firefox-granparadiso | ||
| lightning-sunbird | ||
| midbrowser | ||