Vulnerability record · CVE-2006-3677 · published 27 July 2006
CVE-2006-3677: Mozilla Firefox and SeaMonkey navigator object tampering leads to code execution
Mozilla · Firefox
Firefox 1.5 before 1.5.0.5 and SeaMonkey before 1.0.3 allow remote code execution when certain window.navigator properties are modified and later accessed during Java startup, causing a crash that leads to code execution. The flaw is remotely reachable and needs no authentication, so a malicious page can trigger it in a browsing session.
Description
Mozilla Firefox 1.5 before 1.5.0.5 and SeaMonkey before 1.0.3 allows remote attackers to execute arbitrary code by changing certain properties of the window navigator object (window.navigator) that are accessed when Java starts up, which causes a crash that leads to code execution.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityRemote, unauthenticated code execution with a high EPSS score, though the affected versions are long obsolete and no KEV listing or public exploit tag is present.
What it is
Firefox 1.5 before 1.5.0.5 and SeaMonkey before 1.0.3 allow remote code execution when certain window.navigator properties are modified and later accessed during Java startup, causing a crash that leads to code execution. The flaw is remotely reachable and needs no authentication, so a malicious page can trigger it in a browsing session.
Impact
An attacker can execute arbitrary code with the privileges of the browser process, potentially leading to full system compromise. The CVSS 2.0 vector rates confidentiality, integrity and availability impact as partial.
Attack surface
Reached over the network via a crafted web page that manipulates window.navigator properties before Java starts; no authentication is required, but the victim must load the page and have Java available in the browser.
Exploitation
Not listed in CISA KEV and no ransomware associations are documented; EPSS is high at 0.78685 (99.567th percentile), and references are vendor advisories and patches rather than public exploit tags.
What to do
- Upgrade Firefox to 1.5.0.5 or later and SeaMonkey to 1.0.3 or later, or apply the vendor patches referenced in the advisories.
- Apply the corresponding Linux distribution and vendor security updates (Red Hat, Gentoo, Mandriva, SGI) where the browser packages are affected.
- Disable or remove the Java plugin from the browser if it is not required, since the flaw is triggered during Java startup.
- Restrict browsing to trusted sites and use network controls to reduce exposure to untrusted pages until patching is complete.
Detection
- Monitor browser crash reports for Firefox 1.5 and SeaMonkey crashes involving window.navigator or Java startup.
- Hunt for unexpected child processes or code execution originating from browser processes on hosts running the affected versions.
- Check installed browser versions against the fixed releases (Firefox 1.5.0.5, SeaMonkey 1.0.3) to identify unpatched endpoints.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2006-3677 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2006-3677), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.