The js_dtoa function in Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 overwrites memory instead of exiting when the floating point precision is reduced, which allows remote attackers to cause a denial of service via any plugins that reduce the precision
Published Dec 20, 2006
4.3
MEDIUMCVSS 2.0
EPSS 3.94%
Description
The js_dtoa function in Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 overwrites memory instead of exiting when the floating point precision is reduced, which allows remote attackers to cause a denial of service via any plugins that reduce the precision.
Affected products
No data.
Configuration 1
Configuration 2
- 3.1
- 4.0
Configuration 3
- 5.10
- 6.06
- 6.10
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:M/Au:N/C:N/I:N/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (20 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 3.94% (0.03939) | 90.06th | v5 (v2026.06.15) |
| Jun 15, 2026 | 3.72% (0.03720) | 88.33th | v5 (v2026.06.15) |
| Sep 16, 2025 | 13.71% (0.13714) | 94.03th | v4 (v2025.03.14) |
| Mar 30, 2025 | 23.59% (0.23595) | 95.52th | v4 (v2025.03.14) |
| Mar 29, 2025 | 28.52% (0.28515) | 94.48th | v4 (v2025.03.14) |
| Mar 26, 2025 | 23.59% (0.23595) | 95.46th | v4 (v2025.03.14) |
| Mar 25, 2025 | 6.25% (0.06249) | 89.90th | v4 (v2025.03.14) |
| Mar 17, 2025 | 5.04% (0.05037) | 89.01th | v4 (v2025.03.14) |
| Dec 12, 2024 | 1.99% (0.01995) | 89.30th | v3 (v2023.03.01) |
| Feb 15, 2024 | 1.99% (0.01995) | 88.44th | v3 (v2023.03.01) |
| Dec 23, 2023 | 2.12% (0.02123) | 88.00th | v3 (v2023.03.01) |
| Nov 30, 2023 | 2.09% (0.02093) | 87.89th | v3 (v2023.03.01) |
| Oct 23, 2023 | 1.06% (0.01059) | 82.43th | v3 (v2023.03.01) |
| Sep 15, 2023 | 0.91% (0.00905) | 80.86th | v3 (v2023.03.01) |
| May 23, 2023 | 1.88% (0.01883) | 86.68th | v3 (v2023.03.01) |
| Mar 10, 2023 | 2.03% (0.02027) | 87.13th | v3 (v2023.03.01) |
| Mar 7, 2023 | 1.78% (0.01783) | 86.12th | v3 (v2023.03.01) |
| Mar 6, 2023 | 3.93% (0.03932) | 85.88th | v2 (v2022.01.01) |
| Apr 1, 2022 | 3.93% (0.03932) | 84.43th | v2 (v2022.01.01) |
| Feb 4, 2022 | 3.93% (0.03932) | 67.70th | v2 (v2022.01.01) |
References (34)
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742 vendor-advisoryx_refsource_HPBroken Link
- http://secunia.com/advisories/23282 third-party-advisoryx_refsource_SECUNIABroken LinkThird Party Advisory
- http://secunia.com/advisories/23420 third-party-advisoryx_refsource_SECUNIABroken LinkThird Party Advisory
- http://secunia.com/advisories/23422 third-party-advisoryx_refsource_SECUNIABroken LinkThird Party Advisory
- http://secunia.com/advisories/23545 third-party-advisoryx_refsource_SECUNIABroken LinkThird Party Advisory
- http://secunia.com/advisories/23589 third-party-advisoryx_refsource_SECUNIABroken LinkThird Party Advisory
- http://secunia.com/advisories/23591 third-party-advisoryx_refsource_SECUNIABroken LinkThird Party Advisory
- http://secunia.com/advisories/23614 third-party-advisoryx_refsource_SECUNIABroken LinkThird Party Advisory
- http://secunia.com/advisories/23672 third-party-advisoryx_refsource_SECUNIABroken LinkThird Party Advisory
- http://secunia.com/advisories/23692 third-party-advisoryx_refsource_SECUNIABroken LinkThird Party Advisory
- http://secunia.com/advisories/23988 third-party-advisoryx_refsource_SECUNIABroken LinkThird Party Advisory
- http://secunia.com/advisories/24078 third-party-advisoryx_refsource_SECUNIABroken LinkThird Party Advisory
- http://secunia.com/advisories/24390 third-party-advisoryx_refsource_SECUNIABroken LinkThird Party Advisory
- http://security.gentoo.org/glsa/glsa-200701-02.xml vendor-advisoryx_refsource_GENTOOBroken LinkThird Party Advisory
- http://securitytracker.com/id?1017398 vdb-entryx_refsource_SECTRACKBroken LinkThird Party AdvisoryVDB Entry
- http://securitytracker.com/id?1017405 vdb-entryx_refsource_SECTRACKBroken LinkThird Party AdvisoryVDB Entry
- http://securitytracker.com/id?1017406 vdb-entryx_refsource_SECTRACKBroken LinkThird Party AdvisoryVDB Entry
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-102846-1 vendor-advisoryx_refsource_SUNALERTBroken Link
- http://www.debian.org/security/2007/dsa-1253 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- http://www.debian.org/security/2007/dsa-1258 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- http://www.debian.org/security/2007/dsa-1265 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- http://www.gentoo.org/security/en/glsa/glsa-200701-04.xml vendor-advisoryx_refsource_GENTOOThird Party Advisory
- http://www.kb.cert.org/vuls/id/427972 third-party-advisoryx_refsource_CERT-VNThird Party AdvisoryUS Government Resource
- http://www.mozilla.org/security/announce/2006/mfsa2006-68.html x_refsource_CONFIRMVendor Advisory
- http://www.novell.com/linux/security/advisories/2006_80_mozilla.html vendor-advisoryx_refsource_SUSEBroken Link
- http://www.novell.com/linux/security/advisories/2007_06_mozilla.html vendor-advisoryx_refsource_SUSEBroken Link
- http://www.securityfocus.com/bid/21668 vdb-entryx_refsource_BIDBroken LinkThird Party AdvisoryVDB Entry
- http://www.ubuntu.com/usn/usn-398-1 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- http://www.ubuntu.com/usn/usn-398-2 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- http://www.ubuntu.com/usn/usn-400-1 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- http://www.us-cert.gov/cas/techalerts/TA06-354A.html third-party-advisoryx_refsource_CERTBroken LinkThird Party AdvisoryUS Government Resource
- http://www.vupen.com/english/advisories/2006/5068 vdb-entryx_refsource_VUPENBroken LinkThird Party Advisory
- http://www.vupen.com/english/advisories/2007/1124 vdb-entryx_refsource_VUPENBroken LinkThird Party Advisory
- http://www.vupen.com/english/advisories/2008/0083 vdb-entryx_refsource_VUPENBroken LinkThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742 | vendor-advisoryx_refsource_HPBroken Link | |
| http://secunia.com/advisories/23282 | third-party-advisoryx_refsource_SECUNIABroken LinkThird Party Advisory | |
| http://secunia.com/advisories/23420 | third-party-advisoryx_refsource_SECUNIABroken LinkThird Party Advisory | |
| http://secunia.com/advisories/23422 | third-party-advisoryx_refsource_SECUNIABroken LinkThird Party Advisory | |
| http://secunia.com/advisories/23545 | third-party-advisoryx_refsource_SECUNIABroken LinkThird Party Advisory | |
| http://secunia.com/advisories/23589 | third-party-advisoryx_refsource_SECUNIABroken LinkThird Party Advisory | |
| http://secunia.com/advisories/23591 | third-party-advisoryx_refsource_SECUNIABroken LinkThird Party Advisory | |
| http://secunia.com/advisories/23614 | third-party-advisoryx_refsource_SECUNIABroken LinkThird Party Advisory | |
| http://secunia.com/advisories/23672 | third-party-advisoryx_refsource_SECUNIABroken LinkThird Party Advisory | |
| http://secunia.com/advisories/23692 | third-party-advisoryx_refsource_SECUNIABroken LinkThird Party Advisory | |
| http://secunia.com/advisories/23988 | third-party-advisoryx_refsource_SECUNIABroken LinkThird Party Advisory | |
| http://secunia.com/advisories/24078 | third-party-advisoryx_refsource_SECUNIABroken LinkThird Party Advisory | |
| http://secunia.com/advisories/24390 | third-party-advisoryx_refsource_SECUNIABroken LinkThird Party Advisory | |
| http://security.gentoo.org/glsa/glsa-200701-02.xml | vendor-advisoryx_refsource_GENTOOBroken LinkThird Party Advisory | |
| http://securitytracker.com/id?1017398 | vdb-entryx_refsource_SECTRACKBroken LinkThird Party AdvisoryVDB Entry | |
| http://securitytracker.com/id?1017405 | vdb-entryx_refsource_SECTRACKBroken LinkThird Party AdvisoryVDB Entry | |
| http://securitytracker.com/id?1017406 | vdb-entryx_refsource_SECTRACKBroken LinkThird Party AdvisoryVDB Entry | |
| http://sunsolve.sun.com/search/document.do?assetkey=1-26-102846-1 | vendor-advisoryx_refsource_SUNALERTBroken Link | |
| http://www.debian.org/security/2007/dsa-1253 | vendor-advisoryx_refsource_DEBIANThird Party Advisory | |
| http://www.debian.org/security/2007/dsa-1258 | vendor-advisoryx_refsource_DEBIANThird Party Advisory | |
| http://www.debian.org/security/2007/dsa-1265 | vendor-advisoryx_refsource_DEBIANThird Party Advisory | |
| http://www.gentoo.org/security/en/glsa/glsa-200701-04.xml | vendor-advisoryx_refsource_GENTOOThird Party Advisory | |
| http://www.kb.cert.org/vuls/id/427972 | third-party-advisoryx_refsource_CERT-VNThird Party AdvisoryUS Government Resource | |
| http://www.mozilla.org/security/announce/2006/mfsa2006-68.html | x_refsource_CONFIRMVendor Advisory | |
| http://www.novell.com/linux/security/advisories/2006_80_mozilla.html | vendor-advisoryx_refsource_SUSEBroken Link | |
| http://www.novell.com/linux/security/advisories/2007_06_mozilla.html | vendor-advisoryx_refsource_SUSEBroken Link | |
| http://www.securityfocus.com/bid/21668 | vdb-entryx_refsource_BIDBroken LinkThird Party AdvisoryVDB Entry | |
| http://www.ubuntu.com/usn/usn-398-1 | vendor-advisoryx_refsource_UBUNTUThird Party Advisory | |
| http://www.ubuntu.com/usn/usn-398-2 | vendor-advisoryx_refsource_UBUNTUThird Party Advisory | |
| http://www.ubuntu.com/usn/usn-400-1 | vendor-advisoryx_refsource_UBUNTUThird Party Advisory | |
| http://www.us-cert.gov/cas/techalerts/TA06-354A.html | third-party-advisoryx_refsource_CERTBroken LinkThird Party AdvisoryUS Government Resource | |
| http://www.vupen.com/english/advisories/2006/5068 | vdb-entryx_refsource_VUPENBroken LinkThird Party Advisory | |
| http://www.vupen.com/english/advisories/2007/1124 | vdb-entryx_refsource_VUPENBroken LinkThird Party Advisory | |
| http://www.vupen.com/english/advisories/2008/0083 | vdb-entryx_refsource_VUPENBroken LinkThird Party Advisory |
Change history (0)
No recorded changes yet.