{"api_version":"1","generated_at":"2026-07-23T08:53:03+00:00","cve":"CVE-2006-4569","urls":{"html":"https://cve.report/CVE-2006-4569","api":"https://cve.report/api/cve/CVE-2006-4569.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-4569","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-4569"},"summary":{"title":"CVE-2006-4569","description":"The popup blocker in Mozilla Firefox before 1.5.0.7 opens the \"blocked popups\" display in the context of the Location bar instead of the subframe from which the popup originated, which might make it easier for remote user-assisted attackers to conduct cross-site scripting (XSS) attacks.","state":"PUBLIC","assigner":"secalert@redhat.com","published_at":"2006-09-15 19:07:00","updated_at":"2018-10-17 21:37:00"},"problem_types":["NVD-CWE-Other"],"metrics":[],"references":[{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10650","name":"oval:org.mitre.oval:def:10650","refsource":"OVAL","tags":[],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/22422","name":"22422","refsource":"SECUNIA","tags":[],"title":"Avaya Products Firefox Multiple Vulnerabilities - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://issues.rpath.com/browse/RPL-640","name":"https://issues.rpath.com/browse/RPL-640","refsource":"CONFIRM","tags":[],"title":"[#RPL-640] update to firefox 1.5.0.7 and thunderbird 1.5.0.7 for critical security fixes - rPath JIRA","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://secunia.com/advisories/22025","name":"22025","refsource":"SECUNIA","tags":[],"title":"Ubuntu update for firefox - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/22001","name":"22001","refsource":"SECUNIA","tags":[],"title":"Mandriva update for mozilla-firefox - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/21950","name":"21950","refsource":"SECUNIA","tags":[],"title":"rPath updates for firefox and thunderbird - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.novell.com/linux/security/advisories/2006_54_mozilla.html","name":"SUSE-SA:2006:054","refsource":"SUSE","tags":[],"title":"Security Announcement","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://secunia.com/advisories/22195","name":"22195","refsource":"SECUNIA","tags":[],"title":"Gentoo update for mozilla-firefox - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/21949","name":"21949","refsource":"SECUNIA","tags":["Patch","Vendor Advisory"],"title":"Red Hat update for firefox - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/22066","name":"22066","refsource":"SECUNIA","tags":[],"title":"HP-UX update for firefox - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2007/1198","name":"ADV-2007-1198","refsource":"VUPEN","tags":[],"title":"Webmail - OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://security.gentoo.org/glsa/glsa-200609-19.xml","name":"GLSA-200609-19","refsource":"GENTOO","tags":[],"title":"Gentoo Linux Documentation\n--\n  Mozilla Firefox: Multiple vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.ubuntu.com/usn/usn-354-1","name":"USN-354-1","refsource":"UBUNTU","tags":[],"title":"usn/usn-354-1 - Ubuntu: Linux for human beings","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/446140/100/0/threaded","name":"20060915 rPSA-2006-0169-1 firefox thunderbird","refsource":"BUGTRAQ","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://support.avaya.com/elmodocs2/security/ASA-2006-224.htm","name":"http://support.avaya.com/elmodocs2/security/ASA-2006-224.htm","refsource":"CONFIRM","tags":[],"title":"ASA-2006-224 (RHSA-2006-0675)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2008/0083","name":"ADV-2008-0083","refsource":"VUPEN","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securitytracker.com/id?1016849","name":"1016849","refsource":"SECTRACK","tags":[],"title":"SecurityTracker.com Archives - Mozilla Firefox Input Validation Flaw in Popup Blocking Permits Cross-Site Scripting Attacks","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/28957","name":"firefox-popup-blocker-xss(28957)","refsource":"XF","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.mozilla.org/security/announce/2006/mfsa2006-62.html","name":"http://www.mozilla.org/security/announce/2006/mfsa2006-62.html","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"MFSA 2006-62: Popup-blocker cross-site scripting (XSS)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/22210","name":"22210","refsource":"SECUNIA","tags":[],"title":"Ubuntu update for firefox - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2006/3748","name":"ADV-2006-3748","refsource":"VUPEN","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/24711","name":"24711","refsource":"SECUNIA","tags":[],"title":"Netscape Multiple Vulnerabilities - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/20042","name":"20042","refsource":"BID","tags":[],"title":"Mozilla Firefox/Thunderbird/Seamonkey Multiple Remote Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.ubuntu.com/usn/usn-351-1","name":"USN-351-1","refsource":"UBUNTU","tags":[],"title":"usn/usn-351-1 - Ubuntu: Linux for human beings","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/22056","name":"22056","refsource":"SECUNIA","tags":[],"title":"SUSE updates for MozillaFirefox, MozillaThunderbird, and seamonkey - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.redhat.com/support/errata/RHSA-2006-0675.html","name":"RHSA-2006:0675","refsource":"REDHAT","tags":[],"title":"rhn.redhat.com | Red Hat Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00771742","name":"SSRT061181","refsource":"HP","tags":[],"title":"IT Resource Center - login / register","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.mandriva.com/security/advisories?name=MDKSA-2006:168","name":"MDKSA-2006:168","refsource":"MANDRIVA","tags":[],"title":"Advisories - Mandriva Linux","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-4569","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-4569","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"4569","vulnerable":"1","versionEndIncluding":"1.5.0.6","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mozilla","cpe5":"firefox","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_version":"4.0","data_type":"CVE","data_format":"MITRE","CVE_data_meta":{"ID":"CVE-2006-4569","ASSIGNER":"secalert@redhat.com","STATE":"PUBLIC"},"description":{"description_data":[{"lang":"eng","value":"The popup blocker in Mozilla Firefox before 1.5.0.7 opens the \"blocked popups\" display in the context of the Location bar instead of the subframe from which the popup originated, which might make it easier for remote user-assisted attackers to conduct cross-site scripting (XSS) attacks."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"affects":{"vendor":{"vendor_data":[{"vendor_name":"n/a","product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_affected":"=","version_value":"n/a"}]}}]}}]}},"references":{"reference_data":[{"url":"http://secunia.com/advisories/22066","refsource":"MISC","name":"http://secunia.com/advisories/22066"},{"url":"http://secunia.com/advisories/22210","refsource":"MISC","name":"http://secunia.com/advisories/22210"},{"url":"http://www.ubuntu.com/usn/usn-354-1","refsource":"MISC","name":"http://www.ubuntu.com/usn/usn-354-1"},{"url":"http://www.vupen.com/english/advisories/2006/3748","refsource":"MISC","name":"http://www.vupen.com/english/advisories/2006/3748"},{"url":"http://www.vupen.com/english/advisories/2008/0083","refsource":"MISC","name":"http://www.vupen.com/english/advisories/2008/0083"},{"url":"http://secunia.com/advisories/21949","refsource":"MISC","name":"http://secunia.com/advisories/21949"},{"url":"http://secunia.com/advisories/21950","refsource":"MISC","name":"http://secunia.com/advisories/21950"},{"url":"http://secunia.com/advisories/22001","refsource":"MISC","name":"http://secunia.com/advisories/22001"},{"url":"http://secunia.com/advisories/22025","refsource":"MISC","name":"http://secunia.com/advisories/22025"},{"url":"http://secunia.com/advisories/22056","refsource":"MISC","name":"http://secunia.com/advisories/22056"},{"url":"http://secunia.com/advisories/22195","refsource":"MISC","name":"http://secunia.com/advisories/22195"},{"url":"http://secunia.com/advisories/22422","refsource":"MISC","name":"http://secunia.com/advisories/22422"},{"url":"http://secunia.com/advisories/24711","refsource":"MISC","name":"http://secunia.com/advisories/24711"},{"url":"http://security.gentoo.org/glsa/glsa-200609-19.xml","refsource":"MISC","name":"http://security.gentoo.org/glsa/glsa-200609-19.xml"},{"url":"http://support.avaya.com/elmodocs2/security/ASA-2006-224.htm","refsource":"MISC","name":"http://support.avaya.com/elmodocs2/security/ASA-2006-224.htm"},{"url":"http://www.mandriva.com/security/advisories?name=MDKSA-2006:168","refsource":"MISC","name":"http://www.mandriva.com/security/advisories?name=MDKSA-2006:168"},{"url":"http://www.novell.com/linux/security/advisories/2006_54_mozilla.html","refsource":"MISC","name":"http://www.novell.com/linux/security/advisories/2006_54_mozilla.html"},{"url":"http://www.redhat.com/support/errata/RHSA-2006-0675.html","refsource":"MISC","name":"http://www.redhat.com/support/errata/RHSA-2006-0675.html"},{"url":"http://www.securityfocus.com/archive/1/446140/100/0/threaded","refsource":"MISC","name":"http://www.securityfocus.com/archive/1/446140/100/0/threaded"},{"url":"http://www.ubuntu.com/usn/usn-351-1","refsource":"MISC","name":"http://www.ubuntu.com/usn/usn-351-1"},{"url":"http://www.vupen.com/english/advisories/2007/1198","refsource":"MISC","name":"http://www.vupen.com/english/advisories/2007/1198"},{"url":"http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00771742","refsource":"MISC","name":"http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00771742"},{"url":"https://issues.rpath.com/browse/RPL-640","refsource":"MISC","name":"https://issues.rpath.com/browse/RPL-640"},{"url":"http://www.securityfocus.com/bid/20042","refsource":"MISC","name":"http://www.securityfocus.com/bid/20042"},{"url":"http://securitytracker.com/id?1016849","refsource":"MISC","name":"http://securitytracker.com/id?1016849"},{"url":"http://www.mozilla.org/security/announce/2006/mfsa2006-62.html","refsource":"MISC","name":"http://www.mozilla.org/security/announce/2006/mfsa2006-62.html"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/28957","refsource":"MISC","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/28957"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10650","refsource":"MISC","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10650"}]}},"nvd":{"publishedDate":"2006-09-15 19:07:00","lastModifiedDate":"2018-10-17 21:37:00","problem_types":["NVD-CWE-Other"],"metrics":{"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:H/Au:N/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"HIGH","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":2.6},"severity":"LOW","exploitabilityScore":4.9,"impactScore":2.9,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*","versionEndIncluding":"1.5.0.6","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"4569","Ordinal":"19904","Title":"CVE-2006-4569","CVE":"CVE-2006-4569","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"4569","Ordinal":"1","NoteData":"The popup blocker in Mozilla Firefox before 1.5.0.7 opens the \"blocked popups\" display in the context of the Location bar instead of the subframe from which the popup originated, which might make it easier for remote user-assisted attackers to conduct cross-site scripting (XSS) attacks.","Type":"Description","Title":null},{"CveYear":"2006","CveId":"4569","Ordinal":"2","NoteData":"2006-09-15","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"4569","Ordinal":"3","NoteData":"2018-10-17","Type":"Other","Title":"Modified"}]}}}