CVE-2006-6503Cross-site Scripting in Mozilla Firefox

CWE-25414 documents7 sources
Severity
6.8MEDIUMNVD
EPSS
17.1%
top 4.98%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 20
Latest updateMay 3

Description

Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to bypass cross-site scripting (XSS) protection by changing the src attribute of an IMG element to a javascript: URI.

CVSS vector

AV:N/AC:M/C:P/I:P/A:PExploitability: 8.6 | Impact: 6.4

Affected Packages5 packages

NVDmozilla/firefox1.51.5.0.9+1
NVDmozilla/seamonkey< 1.0.7
NVDmozilla/thunderbird< 1.5.0.9
debiandebian/firefox< firefox 45.0-1 (sid)
debiandebian/firefox-esr< firefox 45.0-1 (sid)

Also affects: Debian Linux 3.1, 4.0, Ubuntu Linux 5.10, 6.06, 6.10

🔴Vulnerability Details

2
GHSA
GHSA-fqqr-pvfq-qprq: Mozilla Firefox 22022-05-03
OSV
CVE-2006-6503: Mozilla Firefox 22006-12-20

📋Vendor Advisories

6
Ubuntu
Firefox regression2007-01-27
Ubuntu
Thunderbird vulnerabilities2007-01-05
Ubuntu
Firefox vulnerabilities2007-01-03
Ubuntu
Firefox vulnerabilities2007-01-03
Red Hat
security flaw2006-12-19

💬Community

5
Bugzilla
CVE-2006-6503 security flaw2018-08-16
Bugzilla
seamonkey < 1.0.7 multiple vulnerabilities2006-12-21
Bugzilla
CVE-2006-6497 Multiple Thunderbird issues (CVE-2006-6498, CVE-2006-6501, CVE-2006-6502, CVE-2006-6503, CVE-2006-6504, CVE-2006-6505)2006-12-14
Bugzilla
CVE-2006-6497 Multiple Seamonkey issues (CVE-2006-6498, CVE-2006-6501, CVE-2006-6502, CVE-2006-6503, CVE-2006-6504, CVE-2006-6505)2006-12-14
Bugzilla
CVE-2006-6497 Multiple Firefox issues (CVE-2006-6498, CVE-2006-6501, CVE-2006-6502, CVE-2006-6503, CVE-2006-6504)2006-12-14