Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2006-5748

16
FAUCET Score

CVE-2006-5748 describes multiple unspecified vulnerabilities in the JavaScript engine of Mozilla Firefox, Thunderbird, and SeaMonkey versions prior to 1.5.0.8, 1.5.0.8, and 1.0.6 respectively. These flaws allow remote attackers to trigger a denial of service (crash) and potentially execute arbitrary code through memory corruption. With a CVSS score of 5.0 (AV:N/AC:L/Au:N/C:N/I:N/A:P), it is a medium severity vulnerability, indicating network-based attacks with low complexity that primarily lead to availability impact. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
1.5CPE matchmatch criteria
cpe:2.3:a:mozilla:firefox:1.5:*:*:*:*:*:*:*
1.5CPE matchmatch criteria
cpe:2.3:a:mozilla:firefox:1.5:beta1:*:*:*:*:*:*
1.5CPE matchmatch criteria
cpe:2.3:a:mozilla:firefox:1.5:beta2:*:*:*:*:*:*
1.5.0.1CPE matchmatch criteria
cpe:2.3:a:mozilla:firefox:1.5.0.1:*:*:*:*:*:*:*
1.5.0.2CPE matchmatch criteria
cpe:2.3:a:mozilla:firefox:1.5.0.2:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

5.0MEDIUM

AV:N/AC:L/Au:N/C:N/I:N/A:P

Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
PARTIAL
Access Vector
NETWORK
Access Complexity
LOW
Authentication
NONE
Exploitability Score
10.0
Impact Score
2.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
5.52%
Probability of exploitation in next 30 days
EPSS Percentile
92.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0552 is in the 89th percentile among its peer group of 23,723 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (10)

debianpatch availablevia nvd_reference
View patch
gentoopatch availablevia nvd_reference
View patch
mozillapatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: devhelp-0:0.10-0.5.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: seamonkey-0:1.0.6-0.1.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: thunderbird-0:1.5.0.8-0.1.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 2.1Fixed in: seamonkey-0:1.0.6-0.1.el2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 3Fixed in: seamonkey-0:1.0.6-0.1.el3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: firefox-0:1.5.0.8-0.1.el4
View patch
ubuntupatch availablevia nvd_reference
View patch

Vendor Advisories (1)

redhatCVE-2006-5748Critical

seamonkey < 1.0.6 multiple vulnerabilities

Nov 8, 2006

References

patches.sgi.com / support/free/security/advisories/20061101-01-P
Patch
rhn.redhat.com / errata/RHSA-2006-0733.html
PatchVendor Advisory
rhn.redhat.com / errata/RHSA-2006-0734.html
PatchVendor Advisory
rhn.redhat.com / errata/RHSA-2006-0735.html
PatchVendor Advisory
bugzilla.mozilla.org / show_bug.cgi
bugzilla.mozilla.org / show_bug.cgi
bugzilla.mozilla.org / show_bug.cgi
bugzilla.mozilla.org / show_bug.cgi
bugzilla.mozilla.org / show_bug.cgi
bugzilla.mozilla.org / show_bug.cgi
bugzilla.mozilla.org / show_bug.cgi
bugzilla.mozilla.org / show_bug.cgi
bugzilla.mozilla.org / show_bug.cgi
secunia.com / advisories/22066
secunia.com / advisories/22722
PatchVendor Advisory
secunia.com / advisories/22727
PatchVendor Advisory
secunia.com / advisories/22737
PatchVendor Advisory
secunia.com / advisories/22763
PatchVendor Advisory
secunia.com / advisories/22770
PatchVendor Advisory
secunia.com / advisories/22774
PatchVendor Advisory
secunia.com / advisories/22815
secunia.com / advisories/22817
PatchVendor Advisory
secunia.com / advisories/22929
PatchVendor Advisory
secunia.com / advisories/22965
PatchVendor Advisory
secunia.com / advisories/22980
PatchVendor Advisory
secunia.com / advisories/23009
PatchVendor Advisory
secunia.com / advisories/23013
PatchVendor Advisory
secunia.com / advisories/23197
PatchVendor Advisory
secunia.com / advisories/23202
PatchVendor Advisory
secunia.com / advisories/23235
PatchVendor Advisory
secunia.com / advisories/23263
Vendor Advisory
secunia.com / advisories/23287
Vendor Advisory
secunia.com / advisories/23297
secunia.com / advisories/24711
secunia.com / advisories/27603
security.gentoo.org / glsa/glsa-200612-06.xml
Patch
security.gentoo.org / glsa/glsa-200612-07.xml
Patch
security.gentoo.org / glsa/glsa-200612-08.xml
securitytracker.com / id
Patch
securitytracker.com / id
Patch
securitytracker.com / id
Patch
exchange.xforce.ibmcloud.com / vulnerabilities/30096
issues.rpath.com / browse/RPL-765
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11408
sunsolve.sun.com / search/document.do
sunsolve.sun.com / search/document.do
support.avaya.com / elmodocs2/security/ASA-2006-246.htm
Patch
www1.itrc.hp.com / service/cki/docDisplay.do
debian.org / security/2006/dsa-1224
Patch
debian.org / security/2006/dsa-1225
PatchVendor Advisory
debian.org / security/2006/dsa-1227
Patch
kb.cert.org / vuls/id/390480
PatchUS Government Resource
mandriva.com / security/advisories
mandriva.com / security/advisories
mozilla.org / security/announce/2006/mfsa2006-65.html
PatchVendor Advisory
novell.com / linux/security/advisories/2006_68_mozilla.html
Patch
securityfocus.com / archive/1/451099/100/0/threaded
securityfocus.com / bid/20957
Patch
ubuntu.com / usn/usn-381-1
PatchVendor Advisory
ubuntu.com / usn/usn-382-1
Patch
us-cert.gov / cas/techalerts/TA06-312A.html
PatchUS Government Resource
vupen.com / english/advisories/2006/3748
vupen.com / english/advisories/2006/4387
vupen.com / english/advisories/2007/1198
vupen.com / english/advisories/2007/3821
vupen.com / english/advisories/2008/0083