Lucene search

K
cveRedhatCVE-2006-1733
HistoryApr 14, 2006 - 10:02 a.m.

CVE-2006-1733

2006-04-1410:02:00
CWE-264
redhat
web.nvd.nist.gov
135
cve
2006
1733
mozilla
firefox
thunderbird
nvd
security
vulnerability
xbl
remote code execution

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

7.3

Confidence

Low

EPSS

0.97

Percentile

99.8%

Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 does not properly protect the compilation scope of privileged built-in XBL bindings, which allows remote attackers to execute arbitrary code via the (1) valueOf.call or (2) valueOf.apply methods of an XBL binding, or (3) “by inserting an XBL method into the DOM’s document.body prototype chain.”

Affected configurations

Nvd
Node
mozillafirefoxRange1.0.7
OR
mozillafirefoxMatch1.0
OR
mozillafirefoxMatch1.0.1
OR
mozillafirefoxMatch1.0.2
OR
mozillafirefoxMatch1.0.3
OR
mozillafirefoxMatch1.0.4
OR
mozillafirefoxMatch1.0.5
OR
mozillafirefoxMatch1.0.6
OR
mozillafirefoxMatch1.5
OR
mozillafirefoxMatch1.5beta1
OR
mozillafirefoxMatch1.5beta2
OR
mozillamozilla_suiteRange1.7.12
OR
mozillamozilla_suiteMatch1.7.6
OR
mozillamozilla_suiteMatch1.7.7
OR
mozillamozilla_suiteMatch1.7.8
OR
mozillamozilla_suiteMatch1.7.10
OR
mozillamozilla_suiteMatch1.7.11
OR
mozillaseamonkeyRange1.0beta
OR
mozillaseamonkeyMatch1.0alpha
OR
mozillathunderbirdRange1.0.7
OR
mozillathunderbirdMatch1.0
OR
mozillathunderbirdMatch1.0.1
OR
mozillathunderbirdMatch1.0.2
OR
mozillathunderbirdMatch1.0.3
OR
mozillathunderbirdMatch1.0.4
OR
mozillathunderbirdMatch1.0.5
OR
mozillathunderbirdMatch1.0.5beta
OR
mozillathunderbirdMatch1.0.6
OR
mozillathunderbirdMatch1.5
OR
mozillathunderbirdMatch1.5beta2
VendorProductVersionCPE
mozillafirefox*cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
mozillafirefox1.0cpe:2.3:a:mozilla:firefox:1.0:*:*:*:*:*:*:*
mozillafirefox1.0.1cpe:2.3:a:mozilla:firefox:1.0.1:*:*:*:*:*:*:*
mozillafirefox1.0.2cpe:2.3:a:mozilla:firefox:1.0.2:*:*:*:*:*:*:*
mozillafirefox1.0.3cpe:2.3:a:mozilla:firefox:1.0.3:*:*:*:*:*:*:*
mozillafirefox1.0.4cpe:2.3:a:mozilla:firefox:1.0.4:*:*:*:*:*:*:*
mozillafirefox1.0.5cpe:2.3:a:mozilla:firefox:1.0.5:*:*:*:*:*:*:*
mozillafirefox1.0.6cpe:2.3:a:mozilla:firefox:1.0.6:*:*:*:*:*:*:*
mozillafirefox1.5cpe:2.3:a:mozilla:firefox:1.5:*:*:*:*:*:*:*
mozillafirefox1.5cpe:2.3:a:mozilla:firefox:1.5:beta1:*:*:*:*:*:*
Rows per page:
1-10 of 301

References

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

7.3

Confidence

Low

EPSS

0.97

Percentile

99.8%