Lucene search

K
cveRedhatCVE-2006-4568
HistorySep 15, 2006 - 7:07 p.m.

CVE-2006-4568

2006-09-1519:07:00
CWE-79
redhat
web.nvd.nist.gov
57
mozilla
firefox
seamonkey
security model
content injection
spoofing
nvd
cve-2006-4568

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

6.1

Confidence

Low

EPSS

0.025

Percentile

90.3%

Mozilla Firefox before 1.5.0.7 and SeaMonkey before 1.0.5 allows remote attackers to bypass the security model and inject content into the sub-frame of another site via targetWindow.frames[n].document.open(), which facilitates spoofing and other attacks.

Affected configurations

Nvd
Node
mozillafirefoxRange1.5.0.6
OR
mozillaseamonkeyRange1.0.4
VendorProductVersionCPE
mozillafirefoxcpe:/a:mozilla:firefox::::
mozillaseamonkeycpe:/a:mozilla:seamonkey::::

References

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

6.1

Confidence

Low

EPSS

0.025

Percentile

90.3%