CVE-2006-6507
published 2006-12-20CVE-2006-6507: Mozilla Firefox 2.0 before 2.0.0.1 allows remote attackers to bypass Cross-Site Scripting (XSS) protection via vectors related to a Function.prototype…
PriorityP413medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.70%
75.0th percentile
Mozilla Firefox 2.0 before 2.0.0.1 allows remote attackers to bypass Cross-Site Scripting (XSS) protection via vectors related to a Function.prototype regression error.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_ubuntu6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-44r5-ph79-43f3: Mozilla Firefox 2
ghsa_unreviewed·2022-05-01
CVE-2006-6507 [MEDIUM] GHSA-44r5-ph79-43f3: Mozilla Firefox 2
Mozilla Firefox 2.0 before 2.0.0.1 allows remote attackers to bypass Cross-Site Scripting (XSS) protection via vectors related to a Function.prototype regression error.
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2007-01-03·CVSS 6.8
CVE-2006-6506 [MEDIUM] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox vulnerabilities
Various flaws have been reported that allow an attacker to execute
arbitrary code with user privileges by tricking the user into opening
a malicious web page containing JavaScript or SVG. (CVE-2006-6497,
CVE-2006-6498, CVE-2006-6499, CVE-2006-6501, CVE-2006-6502,
CVE-2006-6504)
Various flaws have been reported that allow an attacker to bypass
Firefox's internal XSS protections by tricking the user into opening a
malicious web page containing JavaScript. (CVE-2006-6503,
CVE-2006-6507)
Jared Breland discovered that the "Feed Preview" feature could leak
referrer information to remote servers. (CVE-2006-6506)
Instructions: After a standard system upgrade you need to restart Firefox to effect
the necessary changes.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742http://secunia.com/advisories/23282http://secunia.com/advisories/23545http://secunia.com/advisories/23589http://secunia.com/advisories/23614http://secunia.com/advisories/23672http://security.gentoo.org/glsa/glsa-200701-02.xmlhttp://securitytracker.com/id?1017422http://www.mozilla.org/security/announce/2006/mfsa2006-76.htmlhttp://www.novell.com/linux/security/advisories/2006_80_mozilla.htmlhttp://www.novell.com/linux/security/advisories/2007_06_mozilla.htmlhttp://www.securityfocus.com/bid/21668http://www.ubuntu.com/usn/usn-398-1http://www.us-cert.gov/cas/techalerts/TA06-354A.htmlhttp://www.vupen.com/english/advisories/2006/5068http://www.vupen.com/english/advisories/2008/0083http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742http://secunia.com/advisories/23282http://secunia.com/advisories/23545http://secunia.com/advisories/23589http://secunia.com/advisories/23614http://secunia.com/advisories/23672http://security.gentoo.org/glsa/glsa-200701-02.xmlhttp://securitytracker.com/id?1017422http://www.mozilla.org/security/announce/2006/mfsa2006-76.htmlhttp://www.novell.com/linux/security/advisories/2006_80_mozilla.htmlhttp://www.novell.com/linux/security/advisories/2007_06_mozilla.htmlhttp://www.securityfocus.com/bid/21668http://www.ubuntu.com/usn/usn-398-1http://www.us-cert.gov/cas/techalerts/TA06-354A.htmlhttp://www.vupen.com/english/advisories/2006/5068http://www.vupen.com/english/advisories/2008/0083
2006-12-20
Published