CVE-2006-1732Cross-site Scripting in Firefox

17 documents7 sources
Severity
4.3MEDIUMNVD
EPSS
2.2%
top 15.53%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 14
Latest updateMay 3

Description

Unspecified vulnerability in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to bypass same-origin protections and conduct cross-site scripting (XSS) attacks via unspecified vectors involving the window.controllers array.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages6 packages

Debianmozilla/thunderbird< 1.5.0.2-1+3
NVDmozilla/firefox9 versions+8
NVDmozilla/thunderbird9 versions+8
debiandebian/firefox< firefox 1.5.dfsg+1.5.0.2-2 (sid)

Patches

🔴Vulnerability Details

2
GHSA
GHSA-q8q4-prmv-qrjp: Unspecified vulnerability in Mozilla Firefox and Thunderbird 12022-05-03
OSV
CVE-2006-1732: Unspecified vulnerability in Mozilla Firefox and Thunderbird 12006-04-14

📋Vendor Advisories

5
Ubuntu
Thunderbird vulnerabilities2006-05-03
Ubuntu
Mozilla vulnerabilities2006-04-28
Ubuntu
Firefox vulnerabilities2006-04-20
Red Hat
security flaw2006-04-14
Debian
CVE-2006-1732: firefox - Unspecified vulnerability in Mozilla Firefox and Thunderbird 1.x before 1.5 and ...2006

💬Community

9
Bugzilla
CVE-2006-1732 security flaw2018-08-16
Bugzilla
Mozilla Thunderbird multiple vulnerabilities (CVE-2006-0749, CVE-2006-1724, CVE-2006-1730, CVE-2006-0292, et al.)2006-04-22
Bugzilla
multiple critical Firefox, Mozilla vulnerabilities (CVE-2006-0749, CVE-2006-1724, et al.)2006-04-17
Bugzilla
CVE-2006-1732 cross-site scripting through window.controllers2006-04-13
Bugzilla
CVE-2006-1732 cross-site scripting through window.controllers2006-04-13