Lucene search

K
ubuntucveUbuntu.comUB:CVE-2006-1942
HistoryApr 20, 2006 - 12:00 a.m.

CVE-2006-1942

2006-04-2000:00:00
ubuntu.com
ubuntu.com
14

CVSS2

5.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:P/I:P/A:P

EPSS

0.01

Percentile

83.6%

Mozilla Firefox 1.5.0.2 and possibly other versions before 1.5.0.4,
Netscape 8.1, 8.0.4, and 7.2, and K-Meleon 0.9.13 allows user-assisted
remote attackers to open local files via a web page with an IMG element
containing a SRC attribute with a non-image file:// URL, then tricking the
user into selecting View Image for the broken image, as demonstrated using
a .wma file to launch Windows Media Player, or by referencing an “alternate
web page.”

CVSS2

5.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:P/I:P/A:P

EPSS

0.01

Percentile

83.6%