Multiple integer overflows in Mozilla Firefox 1.5, Thunderbird 1.5 if Javascript is enabled in mail, and SeaMonkey before 1.0 might allow remote attackers to execute arbitrary code via the (1) EscapeAttributeValue in jsxml.c for E4X, (2) nsSVGCairoSurface::Init in SVG, and (3) nsCanvasRenderingContext2D.cpp in Canvas.
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1339
https://exchange.xforce.ibmcloud.com/vulnerabilities/24435
https://bugzilla.mozilla.org/show_bug.cgi?id=322215
https://bugzilla.mozilla.org/show_bug.cgi?id=319872
http://www.vupen.com/english/advisories/2006/3749
http://www.vupen.com/english/advisories/2006/0413
http://www.securityfocus.com/bid/16476
http://www.securityfocus.com/archive/1/446657/100/200/threaded
http://www.mozilla.org/security/announce/2006/mfsa2006-06.html
http://securitytracker.com/id?1015570
http://secunia.com/advisories/22065