CVE-2006-3810
Summary
| CVE | CVE-2006-3810 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-07-27 20:04:00 UTC |
| Updated | 2018-10-17 21:31:00 UTC |
| Description | Cross-site scripting (XSS) vulnerability in Mozilla Firefox 1.5 before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 allows remote attackers to inject arbitrary web script or HTML via the XPCNativeWrapper(window).Function construct. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Mozilla | Firefox | 1.5 | All | All | All |
| Application | Mozilla | Firefox | 1.5.0.1 | All | All | All |
| Application | Mozilla | Firefox | 1.5.0.2 | All | All | All |
| Application | Mozilla | Firefox | 1.5.0.3 | All | All | All |
| Application | Mozilla | Firefox | 1.5.0.4 | All | All | All |
| Application | Mozilla | Firefox | 1.5 | All | All | All |
| Application | Mozilla | Firefox | 1.5.0.1 | All | All | All |
| Application | Mozilla | Firefox | 1.5.0.2 | All | All | All |
| Application | Mozilla | Firefox | 1.5.0.3 | All | All | All |
| Application | Mozilla | Firefox | 1.5.0.4 | All | All | All |
| Application | Mozilla | Seamonkey | 1.0 | All | All | All |
| Application | Mozilla | Seamonkey | 1.0 | All | dev | All |
| Application | Mozilla | Seamonkey | 1.0.1 | All | All | All |
| Application | Mozilla | Seamonkey | 1.0.2 | All | All | All |
| Application | Mozilla | Seamonkey | 1.0 | All | All | All |
| Application | Mozilla | Seamonkey | 1.0 | All | dev | All |
| Application | Mozilla | Seamonkey | 1.0.1 | All | All | All |
| Application | Mozilla | Seamonkey | 1.0.2 | All | All | All |
| Application | Mozilla | Thunderbird | 1.5 | All | All | All |
| Application | Mozilla | Thunderbird | 1.5.0.2 | All | All | All |
| Application | Mozilla | Thunderbird | 1.5.0.4 | All | All | All |
| Application | Mozilla | Thunderbird | 1.5 | All | All | All |
| Application | Mozilla | Thunderbird | 1.5.0.2 | All | All | All |
| Application | Mozilla | Thunderbird | 1.5.0.4 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| issues.rpath.com/browse/RPL-537 | CONFIRM | issues.rpath.com | |
| US-CERT Vulnerability Note VU#911004 | CERT-VN | www.kb.cert.org | US Government Resource |
| rhn.redhat.com | Red Hat Support | REDHAT | rhn.redhat.com | |
| Mozilla Firefox Multiple Vulnerabilities - Advisories - Secunia | SECUNIA | secunia.com | Patch, Vendor Advisory |
| USN-329-1: Thunderbird vulnerabilities | Ubuntu security notices | UBUNTU | usn.ubuntu.com | |
| Repository / Oval Repository | OVAL | oval.cisecurity.org | |
| usn/usn-350-1 - Ubuntu: Linux for human beings | UBUNTU | www.ubuntu.com | |
| SecurityFocus | HP | www.securityfocus.com | |
| Mozilla Thunderbird Multiple Vulnerabilities - Advisories - Secunia | SECUNIA | secunia.com | Patch, Vendor Advisory |
| [#RPL-536] update firefox to 1.5.0.5 for security issues - rPath JIRA | CONFIRM | issues.rpath.com | |
| Debian update for mozilla-thunderbird - Advisories - Secunia | SECUNIA | secunia.com | |
| HP-UX update for firefox - Advisories - Secunia | SECUNIA | secunia.com | |
| Debian -- Security Information -- DSA-1159-2 mozilla-thunderbird | DEBIAN | www.debian.org | |
| SecurityFocus | HP | www.securityfocus.com | |
| SecurityTracker.com Archives - Mozilla Seamonkey Multiple Bugs Let Remote Users Execute Arbitrary Code | SECTRACK | securitytracker.com | |
| Gentoo update for seamonkey - Advisories - Secunia | SECUNIA | secunia.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| Mozilla SeaMonkey Multiple Vulnerabilities - Advisories - Secunia | SECUNIA | secunia.com | Patch, Vendor Advisory |
| Debian -- Security Information -- DSA-1160-2 mozilla | DEBIAN | www.debian.org | |
| Mozilla Multiple Products Remote Vulnerabilities | BID | www.securityfocus.com | Patch |
| rhn.redhat.com | Red Hat Support | REDHAT | www.redhat.com | |
| Ubuntu update for mozilla-thunderbird - Advisories - Secunia | SECUNIA | secunia.com | |
| Advisories - Mandriva Linux | MANDRIVA | www.mandriva.com | |
| SUSE update for MozillaFirefox, MozillaThunderbird, and Seamonkey - Advisories - Secunia | SECUNIA | secunia.com | |
| usn/usn-354-1 - Ubuntu: Linux for human beings | UBUNTU | www.ubuntu.com | |
| Red Hat update for seamonkey - Advisories - Secunia | SECUNIA | secunia.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| Ubuntu update for firefox - Advisories - Secunia | SECUNIA | secunia.com | |
| Ubuntu update for firefox - Advisories - Secunia | SECUNIA | secunia.com | |
| rPath update for firefox - Advisories - Secunia | SECUNIA | secunia.com | Patch, Vendor Advisory |
| Mandriva update for mozilla-firefox - Advisories - Secunia | SECUNIA | secunia.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| Gentoo update for mozilla-firefox - Advisories - Secunia | SECUNIA | secunia.com | |
| rhn.redhat.com | Red Hat Support | REDHAT | www.redhat.com | |
| Red Hat update for seamonkey - Advisories - Secunia | SECUNIA | secunia.com | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| rhn.redhat.com | Red Hat Support | REDHAT | www.redhat.com | |
| Mandriva update for mozilla-thunderbird - Advisories - Secunia | SECUNIA | secunia.com | |
| HP-UX update for thunderbird - Advisories - Secunia | SECUNIA | secunia.com | |
| SGI Advanced Linux Environment Multiple Updates - Advisories - Secunia | SECUNIA | secunia.com | |
| Gentoo Linux Documentation -- Mozilla SeaMonkey: Multiple vulnerabilities | GENTOO | security.gentoo.org | |
| rPath update for thunderbird - Advisories - Secunia | SECUNIA | secunia.com | |
| 20060703-01-P | SGI | patches.sgi.com | |
| Security Announcement | SUSE | www.novell.com | |
| Advisories - Mandriva Linux | MANDRIVA | www.mandriva.com | |
| Advisories - Mandriva Linux | MANDRIVA | www.mandriva.com | |
| Debian update for mozilla - Advisories - Secunia | SECUNIA | secunia.com | |
| Gentoo Linux Documentation -- Mozilla Thunderbird: Multiple vulnerabilities | GENTOO | security.gentoo.org | |
| MFSA 2006-54: XSS with XPCNativeWrapper(window).Function(...) | CONFIRM | www.mozilla.org | Vendor Advisory |
| Gentoo update for mozilla-thunderbird - Advisories - Secunia | SECUNIA | secunia.com | |
| SecurityTracker.com Archives - Mozilla Firefox Multiple Bugs Let Remote Users Execute Arbitrary Code | SECTRACK | securitytracker.com | |
| Red Hat update for seamonkey - Advisories - Secunia | SECUNIA | secunia.com | |
| USN-327-1: firefox vulnerabilities | Ubuntu security notices | UBUNTU | usn.ubuntu.com | |
| rhn.redhat.com | Red Hat Support | REDHAT | www.redhat.com | |
| Gentoo Linux Documentation -- Mozilla Firefox: Multiple vulnerabilities | GENTOO | www.gentoo.org | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| Red Hat update for thunderbird - Advisories - Secunia | SECUNIA | secunia.com | |
| Red Hat update for firefox - Advisories - Secunia | SECUNIA | secunia.com | |
| Ubuntu update for thunderbird - Advisories - Secunia | SECUNIA | secunia.com | |
| SecurityTracker.com Archives - Mozilla Thunderbird Multiple Bugs Let Remote Users Execute Arbitrary Code | SECTRACK | securitytracker.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.