CVE-2006-2783Cross-site Scripting in Firefox

CWE-79Cross-site Scripting16 documents7 sources
Severity
4.3MEDIUMNVD
EPSS
5.0%
top 10.30%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 2
Latest updateMay 1

Description

Mozilla Firefox and Thunderbird before 1.5.0.4 strip the Unicode Byte-order-Mark (BOM) from a UTF-8 page before the page is passed to the parser, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a BOM sequence in the middle of a dangerous tag such as SCRIPT.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages5 packages

Debianmozilla/thunderbird< 1.5.0.4-1+3
NVDmozilla/firefox1.5.0.3
NVDmozilla/thunderbird1.5.0.3
debiandebian/firefox< firefox 1.5.dfsg+1.5.0.4-1 (sid)
debiandebian/thunderbird< firefox 1.5.dfsg+1.5.0.4-1 (sid)

🔴Vulnerability Details

2
GHSA
GHSA-776f-3rrc-fhxf: Mozilla Firefox and Thunderbird before 12022-05-01
OSV
CVE-2006-2783: Mozilla Firefox and Thunderbird before 12006-06-02

📋Vendor Advisories

7
Ubuntu
mozilla vulnerabilities2006-07-26
Ubuntu
Thunderbird vulnerabilities2006-07-26
Ubuntu
Firefox vulnerabilities2006-07-25
Ubuntu
Thunderbird vulnerabilities2006-06-14
Ubuntu
firefox vulnerabilities2006-06-09

💬Community

6
Bugzilla
CVE-2006-2783 security flaw2018-08-16
Bugzilla
CVE-2006-2783 multiple Seamonkey issues (CVE-2006-2782,CVE-2006-2778,CVE-2006-2776,CVE-2006-2784,CVE-2006-2785,CVE-2006-2786,CVE-2006-2787,CVE-2006-2788)2006-07-12
Bugzilla
CVE-2006-2779 multiple Thunderbird issues (CVE-2006-2780, CVE-2006-2781, CVE-2006-2783,CVE-2006-2782,CVE-2006-2778,CVE-2006-2776,CVE-2006-2784,CVE-2006-2785,CVE-2006-2786,CVE-2006-2787,CVE-2006-2788)2006-06-28
Bugzilla
CVE-2006-2783 multiple Seamonkey issues (CVE-2006-2782,CVE-2006-2778,CVE-2006-2776,CVE-2006-2784,CVE-2006-2785,CVE-2006-2786,CVE-2006-2787,CVE-2006-2788)2006-06-27
Bugzilla
CVE-2006-2783 multiple Seamonkey issues (CVE-2006-2782,CVE-2006-2778,CVE-2006-2776,CVE-2006-2784,CVE-2006-2785,CVE-2006-2786,CVE-2006-2787,CVE-2006-2788)2006-06-27