CVE-2006-2784Firefox vulnerability

CWE-26414 documents6 sources
Severity
5.1MEDIUMNVD
EPSS
4.0%
top 11.58%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 2
Latest updateMay 1

Description

The PLUGINSPAGE functionality in Mozilla Firefox before 1.5.0.4 allows remote user-assisted attackers to execute privileged code by tricking a user into installing missing plugins and selecting the "Manual Install" button, then using nested javascript: URLs. NOTE: the manual install button is used for downloading software from a remote web site, so this issue would not cross privilege boundaries if the user progresses to the point of installing malicious software from the attacker-controlled sit

CVSS vector

AV:N/AC:H/C:P/I:P/A:PExploitability: 4.9 | Impact: 6.4

Affected Packages2 packages

NVDmozilla/firefox1.5.0.3
debiandebian/firefox< firefox 1.5.dfsg+1.5.0.4-1 (sid)

🔴Vulnerability Details

1
GHSA
GHSA-hh4w-c577-5gx4: The PLUGINSPAGE functionality in Mozilla Firefox before 12022-05-01

📋Vendor Advisories

6
Ubuntu
mozilla vulnerabilities2006-07-26
Ubuntu
Thunderbird vulnerabilities2006-07-26
Ubuntu
Firefox vulnerabilities2006-07-25
Ubuntu
firefox vulnerabilities2006-06-09
Red Hat
security flaw2006-06-01

💬Community

6
Bugzilla
CVE-2006-2784 security flaw2018-08-16
Bugzilla
CVE-2006-2783 multiple Seamonkey issues (CVE-2006-2782,CVE-2006-2778,CVE-2006-2776,CVE-2006-2784,CVE-2006-2785,CVE-2006-2786,CVE-2006-2787,CVE-2006-2788)2006-07-12
Bugzilla
CVE-2006-2779 multiple Thunderbird issues (CVE-2006-2780, CVE-2006-2781, CVE-2006-2783,CVE-2006-2782,CVE-2006-2778,CVE-2006-2776,CVE-2006-2784,CVE-2006-2785,CVE-2006-2786,CVE-2006-2787,CVE-2006-2788)2006-06-28
Bugzilla
CVE-2006-2783 multiple Seamonkey issues (CVE-2006-2782,CVE-2006-2778,CVE-2006-2776,CVE-2006-2784,CVE-2006-2785,CVE-2006-2786,CVE-2006-2787,CVE-2006-2788)2006-06-27
Bugzilla
CVE-2006-2783 multiple Seamonkey issues (CVE-2006-2782,CVE-2006-2778,CVE-2006-2776,CVE-2006-2784,CVE-2006-2785,CVE-2006-2786,CVE-2006-2787,CVE-2006-2788)2006-06-27