{"api_version":"1","generated_at":"2026-07-23T09:00:38+00:00","cve":"CVE-2006-1725","urls":{"html":"https://cve.report/CVE-2006-1725","api":"https://cve.report/api/cve/CVE-2006-1725.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-1725","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-1725"},"summary":{"title":"CVE-2006-1725","description":"Mozilla Firefox 1.5 before 1.5.0.2 and SeaMonkey before 1.0.1 causes certain windows to become translucent due to an interaction between XUL content windows and the history mechanism, which might allow user-assisted remote attackers to trick users into executing arbitrary code.","state":"PUBLISHED","assigner":"redhat","published_at":"2006-04-14 10:02:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["CWE-264","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"2.6","severity":"","vector":"AV:N/AC:H/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:H/Au:N/C:N/I:P/A:N","baseScore":2.6,"accessVector":"NETWORK","accessComplexity":"HIGH","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.vupen.com/english/advisories/2006/3748","name":"http://www.vupen.com/english/advisories/2006/3748","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/22066","name":"http://secunia.com/advisories/22066","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"HP-UX update for firefox - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=327014","name":"https://bugzilla.mozilla.org/show_bug.cgi?id=327014","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking","Vendor Advisory"],"title":"327014 – Clicking <html:a> link in XUL document makes a browser window invisible","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/19631","name":"http://secunia.com/advisories/19631","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Firefox Multiple Vulnerabilities - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2008/0083","name":"http://www.vupen.com/english/advisories/2008/0083","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/446658/100/200/threaded","name":"http://www.securityfocus.com/archive/1/446658/100/200/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2006/1356","name":"http://www.vupen.com/english/advisories/2006/1356","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","Third Party Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.mozilla.org/security/announce/2006/mfsa2006-29.html","name":"http://www.mozilla.org/security/announce/2006/mfsa2006-29.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"MFSA 2006-29: Spoofing with translucent windows","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1471","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1471","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/19649","name":"http://secunia.com/advisories/19649","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","Vendor Advisory"],"title":"Mozilla SeaMonkey Multiple Vulnerabilities - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/17516","name":"http://www.securityfocus.com/bid/17516","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"Mozilla Suite, Firefox, SeaMonkey, and Thunderbird Multiple Remote Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25827","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25827","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-1725","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-1725","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"1725","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mozilla","cpe5":"firefox","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"1725","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mozilla","cpe5":"seamonkey","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2006","cve_id":"1725","cve":"CVE-2006-1725","epss":"0.022340000","percentile":"0.809350000","score_date":"2026-07-22","updated_at":"2026-07-23 00:09:35"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T17:19:49.522Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_MISC","x_transferred"],"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=327014"},{"name":"ADV-2006-3748","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2006/3748"},{"name":"ADV-2008-0083","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2008/0083"},{"name":"SSRT061181","tags":["vendor-advisory","x_refsource_HP","x_transferred"],"url":"http://www.securityfocus.com/archive/1/446658/100/200/threaded"},{"name":"mozilla-xul-window-spoofing(25827)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25827"},{"name":"ADV-2006-1356","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2006/1356"},{"name":"HPSBUX02153","tags":["vendor-advisory","x_refsource_HP","x_transferred"],"url":"http://www.securityfocus.com/archive/1/446658/100/200/threaded"},{"name":"19649","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/19649"},{"name":"oval:org.mitre.oval:def:1471","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1471"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.mozilla.org/security/announce/2006/mfsa2006-29.html"},{"name":"17516","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/17516"},{"name":"22066","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/22066"},{"name":"19631","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/19631"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2006-04-13T00:00:00.000Z","descriptions":[{"lang":"en","value":"Mozilla Firefox 1.5 before 1.5.0.2 and SeaMonkey before 1.0.1 causes certain windows to become translucent due to an interaction between XUL content windows and the history mechanism, which might allow user-assisted remote attackers to trick users into executing arbitrary code."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-18T14:57:01.000Z","orgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","shortName":"redhat"},"references":[{"tags":["x_refsource_MISC"],"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=327014"},{"name":"ADV-2006-3748","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2006/3748"},{"name":"ADV-2008-0083","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2008/0083"},{"name":"SSRT061181","tags":["vendor-advisory","x_refsource_HP"],"url":"http://www.securityfocus.com/archive/1/446658/100/200/threaded"},{"name":"mozilla-xul-window-spoofing(25827)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25827"},{"name":"ADV-2006-1356","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2006/1356"},{"name":"HPSBUX02153","tags":["vendor-advisory","x_refsource_HP"],"url":"http://www.securityfocus.com/archive/1/446658/100/200/threaded"},{"name":"19649","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/19649"},{"name":"oval:org.mitre.oval:def:1471","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1471"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.mozilla.org/security/announce/2006/mfsa2006-29.html"},{"name":"17516","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/17516"},{"name":"22066","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/22066"},{"name":"19631","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/19631"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"secalert@redhat.com","ID":"CVE-2006-1725","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Mozilla Firefox 1.5 before 1.5.0.2 and SeaMonkey before 1.0.1 causes certain windows to become translucent due to an interaction between XUL content windows and the history mechanism, which might allow user-assisted remote attackers to trick users into executing arbitrary code."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"https://bugzilla.mozilla.org/show_bug.cgi?id=327014","refsource":"MISC","url":"https://bugzilla.mozilla.org/show_bug.cgi?id=327014"},{"name":"ADV-2006-3748","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2006/3748"},{"name":"ADV-2008-0083","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2008/0083"},{"name":"SSRT061181","refsource":"HP","url":"http://www.securityfocus.com/archive/1/446658/100/200/threaded"},{"name":"mozilla-xul-window-spoofing(25827)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25827"},{"name":"ADV-2006-1356","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2006/1356"},{"name":"HPSBUX02153","refsource":"HP","url":"http://www.securityfocus.com/archive/1/446658/100/200/threaded"},{"name":"19649","refsource":"SECUNIA","url":"http://secunia.com/advisories/19649"},{"name":"oval:org.mitre.oval:def:1471","refsource":"OVAL","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1471"},{"name":"http://www.mozilla.org/security/announce/2006/mfsa2006-29.html","refsource":"CONFIRM","url":"http://www.mozilla.org/security/announce/2006/mfsa2006-29.html"},{"name":"17516","refsource":"BID","url":"http://www.securityfocus.com/bid/17516"},{"name":"22066","refsource":"SECUNIA","url":"http://secunia.com/advisories/22066"},{"name":"19631","refsource":"SECUNIA","url":"http://secunia.com/advisories/19631"}]}}}},"cveMetadata":{"assignerOrgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","assignerShortName":"redhat","cveId":"CVE-2006-1725","datePublished":"2006-04-14T10:00:00.000Z","dateReserved":"2006-04-12T00:00:00.000Z","dateUpdated":"2024-08-07T17:19:49.522Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2006-04-14 10:02:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["CWE-264","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:H/Au:N/C:N/I:P/A:N","baseScore":2.6,"accessVector":"NETWORK","accessComplexity":"HIGH","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":4.9,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*","versionStartIncluding":"1.5","versionEndExcluding":"1.5.0.2","matchCriteriaId":"04455349-5186-4BF4-8EE1-F4852B806F47"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:*","versionEndExcluding":"1.0.1","matchCriteriaId":"976B9AFA-0129-480B-B226-892CECD59287"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"1725","Ordinal":"1","Title":"CVE-2006-1725","CVE":"CVE-2006-1725","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"1725","Ordinal":"1","NoteData":"Mozilla Firefox 1.5 before 1.5.0.2 and SeaMonkey before 1.0.1 causes certain windows to become translucent due to an interaction between XUL content windows and the history mechanism, which might allow user-assisted remote attackers to trick users into executing arbitrary code.","Type":"Description","Title":"CVE-2006-1725"},{"CveYear":"2006","CveId":"1725","Ordinal":"2","NoteData":"2006-04-14","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"1725","Ordinal":"3","NoteData":"2018-10-18","Type":"Other","Title":"Modified"}]}}}