CVE-2006-1736
Summary
| CVE | CVE-2006-1736 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-04-14 10:02:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | Mozilla Firefox 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to trick users into downloading and saving an executable file via an image that is overlaid by a transparent image link that points to the executable, which causes the executable to be saved when the user clicks the "Save image as..." option. NOTE: this attack is made easier due to a GUI truncation issue that prevents the user from seeing the malicious extension when there is extra whitespace in the filename. |
Risk And Classification
Primary CVSS: v2.0 2.6 from [email protected]
AV:N/AC:H/Au:N/C:N/I:P/A:N
EPSS: 0.016230000 probability, percentile 0.819060000 (date 2026-04-23)
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
HighAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:H/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Mozilla | Firefox | 1.0 | All | All | All |
| Application | Mozilla | Firefox | 1.0.1 | All | All | All |
| Application | Mozilla | Firefox | 1.0.2 | All | All | All |
| Application | Mozilla | Firefox | 1.0.3 | All | All | All |
| Application | Mozilla | Firefox | 1.0.4 | All | All | All |
| Application | Mozilla | Firefox | 1.0.5 | All | All | All |
| Application | Mozilla | Firefox | 1.0.6 | All | All | All |
| Application | Mozilla | Firefox | 1.5 | All | All | All |
| Application | Mozilla | Firefox | 1.5 | beta1 | All | All |
| Application | Mozilla | Firefox | 1.5 | beta2 | All | All |
| Application | Mozilla | Firefox | All | All | All | All |
| Application | Mozilla | Mozilla Suite | 1.7.10 | All | All | All |
| Application | Mozilla | Mozilla Suite | 1.7.11 | All | All | All |
| Application | Mozilla | Mozilla Suite | 1.7.6 | All | All | All |
| Application | Mozilla | Mozilla Suite | 1.7.7 | All | All | All |
| Application | Mozilla | Mozilla Suite | 1.7.8 | All | All | All |
| Application | Mozilla | Mozilla Suite | All | All | All | All |
| Application | Mozilla | Seamonkey | 1.0 | All | alpha | All |
| Application | Mozilla | Seamonkey | All | beta | All | All |
| Application | Mozilla | Thunderbird | 1.0 | All | All | All |
| Application | Mozilla | Thunderbird | 1.0.1 | All | All | All |
| Application | Mozilla | Thunderbird | 1.0.2 | All | All | All |
| Application | Mozilla | Thunderbird | 1.0.3 | All | All | All |
| Application | Mozilla | Thunderbird | 1.0.4 | All | All | All |
| Application | Mozilla | Thunderbird | 1.0.5 | All | All | All |
| Application | Mozilla | Thunderbird | 1.0.5 | beta | All | All |
| Application | Mozilla | Thunderbird | 1.0.6 | All | All | All |
| Application | Mozilla | Thunderbird | 1.5 | All | All | All |
| Application | Mozilla | Thunderbird | 1.5 | beta2 | All | All |
| Application | Mozilla | Thunderbird | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SUSE update for mozilla/firefox - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Ubuntu update for mozilla - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Debian update for mozilla-thunderbird - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Sun Solaris update for mozilla - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Debian -- Security Information -- DSA-1051-1 mozilla-thunderbird | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| Gentoo Linux Documentation -- Mozilla Suite: Multiple vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.gentoo.org | |
| Mandriva update for firefox - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| ASA-2006-205 (SUN 102502, 102513, 102514, 102519, 102550, 102556, 102557, 102582, 102588, 102589, 102593) | af854a3a-2127-422b-91ae-364da2661108 | support.avaya.com | |
| sunsolve.sun.com/search/document.do | af854a3a-2127-422b-91ae-364da2661108 | sunsolve.sun.com | |
| Debian -- Security Information -- DSA-1044-1 mozilla-firefox | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| MFSA 2006-13: Downloading executables with "Save Image As..." | af854a3a-2127-422b-91ae-364da2661108 | www.mozilla.org | |
| Gentoo update for mozilla - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Advisories - Mandriva Linux | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| 293527 – "Save Image As" context menu allows to silently save executables instead of images | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | |
| Debian update for mozilla - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Firefox Multiple Vulnerabilities - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Ubuntu update for firefox - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.26/SCOSA-2006.26.txt | af854a3a-2127-422b-91ae-364da2661108 | ftp.sco.com | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| Gentoo update for mozilla-firefox / mozilla-firefox-bin - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| SuSE Security announcements: [suse-security-announce] SUSE Security Announcement: Mozilla Firefox, Mozilla Suite various problems (SUSE-SA:2006:021) | af854a3a-2127-422b-91ae-364da2661108 | lists.suse.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| USN-275-1: Mozilla vulnerabilities | Ubuntu security notices | af854a3a-2127-422b-91ae-364da2661108 | usn.ubuntu.com | |
| Gentoo Linux Documentation -- Mozilla Firefox: Multiple vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.gentoo.org | |
| Debian -- Security Information -- DSA-1046-1 mozilla | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| Advisories - Mandriva Linux | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| UnixWare update for mozilla - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Mozilla Suite, Firefox, SeaMonkey, and Thunderbird Multiple Remote Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| #102550: Multiple Security Vulnerabilites in Mozilla 1.4 and 1.7 for Solaris and for Sun JDS for Linux | af854a3a-2127-422b-91ae-364da2661108 | sunsolve.sun.com | |
| Debian update for mozilla-firefox - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| USN-271-1: Firefox vulnerabilities | Ubuntu security notices | af854a3a-2127-422b-91ae-364da2661108 | usn.ubuntu.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.