Lucene search

K
ubuntucveUbuntu.comUB:CVE-2006-1731
HistoryApr 14, 2006 - 12:00 a.m.

CVE-2006-1731

2006-04-1400:00:00
ubuntu.com
ubuntu.com
15

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS

0.205

Percentile

96.4%

Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8,
Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 returns the Object
class prototype instead of the global window object when (1) .valueOf.call
or (2) .valueOf.apply are called without any arguments, which allows remote
attackers to conduct cross-site scripting (XSS) attacks.

OSVersionArchitecturePackageVersionFilename
ubuntu6.06noarchfirefox< 1.5.dfsg+1.5.0.13~prepatch070731-0ubuntu1UNKNOWN
ubuntu6.06noarchmozilla-thunderbird< 1.5.0.13-0ubuntu0.6.06UNKNOWN
ubuntu6.10noarchmozilla-thunderbird< 1.5.0.13-0ubuntu0.6.10UNKNOWN
ubuntu7.04noarchmozilla-thunderbird< 1.5.0.13-0ubuntu0.7.04UNKNOWN

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS

0.205

Percentile

96.4%