CVE-2006-4568Cross-site Scripting in Firefox

CWE-79Cross-site Scripting14 documents7 sources
Severity
4.3MEDIUMNVD
EPSS
1.4%
top 19.83%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 15
Latest updateMay 3

Description

Mozilla Firefox before 1.5.0.7 and SeaMonkey before 1.0.5 allows remote attackers to bypass the security model and inject content into the sub-frame of another site via targetWindow.frames[n].document.open(), which facilitates spoofing and other attacks.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages5 packages

NVDmozilla/firefox2.0.0.4+41
debiandebian/firefox< firefox 1.5.dfsg+1.5.0.7-1 (sid)
Debianmozilla/thunderbird< 1.5.0.7-1+3
debiandebian/thunderbird< firefox 1.5.dfsg+1.5.0.7-1 (sid)

Patches

🔴Vulnerability Details

3
GHSA
GHSA-w739-3fq5-fgvp: Mozilla Firefox before 22022-05-03
GHSA
GHSA-xg52-wr75-9hc5: Mozilla Firefox before 12022-05-03
OSV
CVE-2006-4568: Mozilla Firefox before 12006-09-15

📋Vendor Advisories

5
Red Hat
security flaw2007-06-04
Ubuntu
Mozilla vulnerabilities2006-10-10
Ubuntu
firefox vulnerabilities2006-09-23
Red Hat
security flaw2006-09-15
Debian
CVE-2006-4568: firefox - Mozilla Firefox before 1.5.0.7 and SeaMonkey before 1.0.5 allows remote attacker...2006

💬Community

4
Bugzilla
CVE-2007-3089 security flaw2018-08-16
Bugzilla
CVE-2006-4568 security flaw2018-08-16
Bugzilla
CVE-2006-4340 Various SeaMonkey security issues (CVE-2006-4253 CVE-2006-4565 CVE-2006-4566 CVE-2006-4568 CVE-2006-4570 CVE-2006-4571)2006-09-14
Bugzilla
CVE-2006-4340 Various Firefox security issues (CVE-2006-4253 CVE-2006-4565 CVE-2006-4566 CVE-2006-4567 CVE-2006-4568 CVE-2006-4569 CVE-2006-4571)2006-09-14