CVE-2006-4569
published 2006-09-15CVE-2006-4569: The popup blocker in Mozilla Firefox before 1.5.0.7 opens the "blocked popups" display in the context of the Location bar instead of the subframe from which…
PriorityP47low2.6CVSS 2.0
AVNACHAuNCNIPAN
EPSS
2.13%
79.7th percentile
The popup blocker in Mozilla Firefox before 1.5.0.7 opens the "blocked popups" display in the context of the Location bar instead of the subframe from which the popup originated, which might make it easier for remote user-assisted attackers to conduct cross-site scripting (XSS) attacks.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | < firefox 1.5.dfsg+1.5.0.7-1 (sid) | firefox 1.5.dfsg+1.5.0.7-1 (sid) |
| debian | thunderbird | < firefox 1.5.dfsg+1.5.0.7-1 (sid) | firefox 1.5.dfsg+1.5.0.7-1 (sid) |
| mozilla | firefox | <= 1.5.0.6 | — |
| mozilla | thunderbird | >= 0 < 1.5.0.7-1 | 1.5.0.7-1 |
| mozilla | thunderbird | >= 0 < 1.5.0.7-1 | 1.5.0.7-1 |
| mozilla | thunderbird | >= 0 < 1.5.0.7-1 | 1.5.0.7-1 |
| mozilla | thunderbird | >= 0 < 1.5.0.7-1 | 1.5.0.7-1 |
CVSS provenance
nvdv2.02.6LOWAV:N/AC:H/Au:N/C:N/I:P/A:N
osv2.6LOW
vendor_ubuntu7.6HIGH
vendor_debian2.6LOW
vendor_redhat2.6LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9m24-j378-4w43: The popup blocker in Mozilla Firefox before 1
ghsa_unreviewed·2022-05-01
CVE-2006-4569 [LOW] GHSA-9m24-j378-4w43: The popup blocker in Mozilla Firefox before 1
The popup blocker in Mozilla Firefox before 1.5.0.7 opens the "blocked popups" display in the context of the Location bar instead of the subframe from which the popup originated, which might make it easier for remote user-assisted attackers to conduct cross-site scripting (XSS) attacks.
OSV
CVE-2006-4569: The popup blocker in Mozilla Firefox before 1
osv·2006-09-15·CVSS 2.6
CVE-2006-4569 [LOW] CVE-2006-4569: The popup blocker in Mozilla Firefox before 1
The popup blocker in Mozilla Firefox before 1.5.0.7 opens the "blocked popups" display in the context of the Location bar instead of the subframe from which the popup originated, which might make it easier for remote user-assisted attackers to conduct cross-site scripting (XSS) attacks.
Ubuntu
firefox vulnerabilities
vendor_ubuntu·2006-09-23·CVSS 7.6
CVE-2006-4571 [HIGH] firefox vulnerabilities
Title: firefox vulnerabilities
Summary: firefox vulnerabilities
Various flaws have been reported that allow an attacker to execute
arbitrary code with user privileges by tricking the user into opening
a malicious web page containing JavaScript. (CVE-2006-4253,
CVE-2006-4565, CVE-2006-4566, CVE-2006-4568, CVE-2006-4569
CVE-2006-4571)
The NSS library did not sufficiently check the padding of PKCS #1 v1.5
signatures if the exponent of the public key is 3 (which is widely
used for CAs). This could be exploited to forge valid signatures
without the need of the secret key. (CVE-2006-4340)
Jon Oberheide reported a way how a remote attacker could trick users
into downloading arbitrary extensions with circumventing the normal
SSL certificate check. The attacker would have to be in a position to
Red Hat
security flaw
vendor_redhat·2006-09-15·CVSS 2.6
CVE-2006-4569 [LOW] security flaw
security flaw
The popup blocker in Mozilla Firefox before 1.5.0.7 opens the "blocked popups" display in the context of the Location bar instead of the subframe from which the popup originated, which might make it easier for remote user-assisted attackers to conduct cross-site scripting (XSS) attacks.
Debian
CVE-2006-4569: firefox - The popup blocker in Mozilla Firefox before 1.5.0.7 opens the "blocked popups" d...
vendor_debian·2006·CVSS 2.6
CVE-2006-4569 [LOW] CVE-2006-4569: firefox - The popup blocker in Mozilla Firefox before 1.5.0.7 opens the "blocked popups" d...
The popup blocker in Mozilla Firefox before 1.5.0.7 opens the "blocked popups" display in the context of the Location bar instead of the subframe from which the popup originated, which might make it easier for remote user-assisted attackers to conduct cross-site scripting (XSS) attacks.
Scope: local
sid: resolved (fixed in 1.5.dfsg+1.5.0.7-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2006-4569 security flaw
bugzilla·2018-08-16·CVSS 2.6
CVE-2006-4569 [LOW] CVE-2006-4569 security flaw
CVE-2006-4569 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
The popup blocker in Mozilla Firefox before 1.5.0.7 opens the "blocked popups" display in the context of the Location bar instead of the subframe from which the popup originated, which might make it easier for remote user-assisted attackers to conduct cross-site scripting (XSS) attacks.
Bugzilla
CVE-2006-4340 Various Firefox security issues (CVE-2006-4253 CVE-2006-4565 CVE-2006-4566 CVE-2006-4567 CVE-2006-4568 CVE-2006-4569 CVE-2006-4571)
bugzilla·2006-09-14·CVSS 7.6
CVE-2006-4340 [HIGH] CVE-2006-4340 Various Firefox security issues (CVE-2006-4253 CVE-2006-4565 CVE-2006-4566 CVE-2006-4567 CVE-2006-4568 CVE-2006-4569 CVE-2006-4571)
CVE-2006-4340 Various Firefox security issues (CVE-2006-4253 CVE-2006-4565 CVE-2006-4566 CVE-2006-4567 CVE-2006-4568 CVE-2006-4569 CVE-2006-4571)
** MFSA-2006-57 **
Two flaws were found in the way Firefox processed certain
regular expressions. A malicious web page could crash the
browser or possibly execute arbitrary code as the user running
Firefox. (CVE-2006-4565, CVE-2006-4566)
CVE-2006-4565 https://bugzilla.mozilla.org/show_bug.cgi?id=346090
CVE-2006-4566 https://bugzilla.mozilla.org/show_bug.cgi?id=346794
impact=critical,public=20060914
** MFSA-2006-58 **
A flaw was found in the Firefox auto-update verfication
system. An attacker who has the ability to spoof a victim's
DNS could get Firefox to download and install malicious code.
In order to exploit this issue an attacker would a
http://secunia.com/advisories/21949http://secunia.com/advisories/21950http://secunia.com/advisories/22001http://secunia.com/advisories/22025http://secunia.com/advisories/22056http://secunia.com/advisories/22066http://secunia.com/advisories/22195http://secunia.com/advisories/22210http://secunia.com/advisories/22422http://secunia.com/advisories/24711http://security.gentoo.org/glsa/glsa-200609-19.xmlhttp://securitytracker.com/id?1016849http://support.avaya.com/elmodocs2/security/ASA-2006-224.htmhttp://www.mandriva.com/security/advisories?name=MDKSA-2006:168http://www.mozilla.org/security/announce/2006/mfsa2006-62.htmlhttp://www.novell.com/linux/security/advisories/2006_54_mozilla.htmlhttp://www.redhat.com/support/errata/RHSA-2006-0675.htmlhttp://www.securityfocus.com/archive/1/446140/100/0/threadedhttp://www.securityfocus.com/bid/20042http://www.ubuntu.com/usn/usn-351-1http://www.ubuntu.com/usn/usn-354-1http://www.vupen.com/english/advisories/2006/3748http://www.vupen.com/english/advisories/2007/1198http://www.vupen.com/english/advisories/2008/0083http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00771742https://exchange.xforce.ibmcloud.com/vulnerabilities/28957https://issues.rpath.com/browse/RPL-640https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10650http://secunia.com/advisories/21949http://secunia.com/advisories/21950http://secunia.com/advisories/22001http://secunia.com/advisories/22025http://secunia.com/advisories/22056http://secunia.com/advisories/22066http://secunia.com/advisories/22195http://secunia.com/advisories/22210http://secunia.com/advisories/22422http://secunia.com/advisories/24711http://security.gentoo.org/glsa/glsa-200609-19.xmlhttp://securitytracker.com/id?1016849http://support.avaya.com/elmodocs2/security/ASA-2006-224.htmhttp://www.mandriva.com/security/advisories?name=MDKSA-2006:168http://www.mozilla.org/security/announce/2006/mfsa2006-62.htmlhttp://www.novell.com/linux/security/advisories/2006_54_mozilla.htmlhttp://www.redhat.com/support/errata/RHSA-2006-0675.htmlhttp://www.securityfocus.com/archive/1/446140/100/0/threadedhttp://www.securityfocus.com/bid/20042http://www.ubuntu.com/usn/usn-351-1http://www.ubuntu.com/usn/usn-354-1http://www.vupen.com/english/advisories/2006/3748http://www.vupen.com/english/advisories/2007/1198http://www.vupen.com/english/advisories/2008/0083http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00771742https://exchange.xforce.ibmcloud.com/vulnerabilities/28957https://issues.rpath.com/browse/RPL-640https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10650
2006-09-15
Published