CVE-2006-3810Cross-site Scripting in Firefox

17 documents7 sources
Severity
6.8MEDIUMNVD
EPSS
13.6%
top 5.73%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 27
Latest updateMay 3

Description

Cross-site scripting (XSS) vulnerability in Mozilla Firefox 1.5 before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 allows remote attackers to inject arbitrary web script or HTML via the XPCNativeWrapper(window).Function construct.

CVSS vector

AV:N/AC:M/C:P/I:P/A:PExploitability: 8.6 | Impact: 6.4

Affected Packages6 packages

Debianmozilla/thunderbird< 1.5.0.5-1+3
NVDmozilla/firefox5 versions+4
NVDmozilla/seamonkey1.0, 1.0.1, 1.0.2+2
NVDmozilla/thunderbird1.5, 1.5.0.2, 1.5.0.4+2
debiandebian/firefox< firefox 1.5.dfsg+1.5.0.5-1 (sid)

Patches

🔴Vulnerability Details

2
GHSA
GHSA-4x7f-g374-66v2: Cross-site scripting (XSS) vulnerability in Mozilla Firefox 12022-05-03
OSV
CVE-2006-3810: Cross-site scripting (XSS) vulnerability in Mozilla Firefox 12006-07-27

📋Vendor Advisories

5
Ubuntu
Thunderbird vulnerabilities2006-09-22
Ubuntu
Thunderbird vulnerabilities2006-07-29
Ubuntu
firefox vulnerabilities2006-07-28
Red Hat
security flaw2006-07-26
Debian
CVE-2006-3810: firefox - Cross-site scripting (XSS) vulnerability in Mozilla Firefox 1.5 before 1.5.0.5, ...2006

💬Community

9
Bugzilla
CVE-2006-3810 security flaw2018-08-16
Bugzilla
Seamonkey multiple vulnerabilities: CVE-2006-{3113,3677,3801-3812}2006-07-27
Bugzilla
major (public) security flaws fixed in firefox 1.5.0.5: CVE-2006-3113, CVE-2006-3677, CVE-2006-3801, CVE-2006-3802, CVE-2006-3803,CVE-2006-3805, CVE-2006-3806, CVE-2006-3807, CVE-2006-3808, CVE-2006-32006-07-27
Bugzilla
CVE-2006-3801 Multiple Seamonkey issues (CVE-2006-3677, CVE-2006-3113, CVE-2006-3802, CVE-2006-3803, CVE-2006-3804, CVE-2006-3805, CVE-2006-3806, CVE-2006-3807, CVE-2006-3808, CVE-2006-3809, CVE-2006-2006-07-26
Bugzilla
CVE-2006-3801 Multiple Seamonkey issues (CVE-2006-3677, CVE-2006-3113, CVE-2006-3802, CVE-2006-3803, CVE-2006-3804, CVE-2006-3805, CVE-2006-3806, CVE-2006-3807, CVE-2006-3808, CVE-2006-3809, CVE-2006-2006-07-25