cbcvebase.
CVE-2006-2783
published 2006-06-02

CVE-2006-2783: Mozilla Firefox and Thunderbird before 1.5.0.4 strip the Unicode Byte-order-Mark (BOM) from a UTF-8 page before the page is passed to the parser, which allows…

PriorityP412medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.67%
74.0th percentile
Mozilla Firefox and Thunderbird before 1.5.0.4 strip the Unicode Byte-order-Mark (BOM) from a UTF-8 page before the page is passed to the parser, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a BOM sequence in the middle of a dangerous tag such as SCRIPT.

Affected

8 ranges
VendorProductVersion rangeFixed in
debianfirefox< firefox 1.5.dfsg+1.5.0.4-1 (sid)firefox 1.5.dfsg+1.5.0.4-1 (sid)
debianthunderbird< firefox 1.5.dfsg+1.5.0.4-1 (sid)firefox 1.5.dfsg+1.5.0.4-1 (sid)
mozillafirefox<= 1.5.0.3
mozillathunderbird<= 1.5.0.3
mozillathunderbird>= 0 < 1.5.0.4-11.5.0.4-1
mozillathunderbird>= 0 < 1.5.0.4-11.5.0.4-1
mozillathunderbird>= 0 < 1.5.0.4-11.5.0.4-1
mozillathunderbird>= 0 < 1.5.0.4-11.5.0.4-1

CVSS provenance

nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_ubuntu7.5HIGH
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.