CVE-2006-1741

Severity
4.3MEDIUM
EPSS
1.9%
top 16.55%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 14
Latest updateMay 3

Description

Mozilla Firefox 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to inject arbitrary Javascript into other sites by (1) "using a modal alert to suspend an event handler while a new page is being loaded", (2) using eval(), and using certain variants involving (3) "new Script;" and (4) using window.__proto__ to extend eval, aka "cross-site JavaScript injection".

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages4 packages

NVDmozilla/firefox1.01.0.8+1
NVDmozilla/mozilla_suite< 1.7.13
Debianthunderbird< 1.5.0.2-1+3

Also affects: Ubuntu Linux 4.10, 5.04, 5.10

🔴Vulnerability Details

3
GHSA
GHSA-8r79-mxmm-hhc6: Mozilla Firefox 12022-05-03
CVEList
CVE-2006-1741: Mozilla Firefox 12006-04-14
OSV
CVE-2006-1741: Mozilla Firefox 12006-04-14

📋Vendor Advisories

5
Ubuntu
Thunderbird vulnerabilities2006-05-03
Ubuntu
Mozilla vulnerabilities2006-04-28
Ubuntu
Firefox vulnerabilities2006-04-20
Red Hat
security flaw2006-04-14
Debian
CVE-2006-1741: firefox - Mozilla Firefox 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7....2006

💬Community

7
Bugzilla
CVE-2006-1741 security flaw2018-08-16
Bugzilla
CVE-2006-1741 Cross-site JavaScript injection using event handlers2006-04-13
Bugzilla
CVE-2006-1741 Cross-site JavaScript injection using event handlers2006-04-13
Bugzilla
CVE-2006-1741 Cross-site JavaScript injection using event handlers2006-04-13
Bugzilla
CVE-2006-1741 Cross-site JavaScript injection using event handlers2006-04-13
CVE-2006-1741 (MEDIUM CVSS 4.3) | Mozilla Firefox 1.x before 1.5 and | cvebase.io