CVE Database
/

CVE-2006-1736

Back to search

CVE-2006-1736

Published: Apr 14, 2006

Modified: Aug 7, 2024

PUBLISHED

Description

Mozilla Firefox 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to trick users into downloading and saving an executable file via an image that is overlaid by a transparent image link that points to the executable, which causes the executable to be saved when the user clicks the "Save image as..." option. NOTE: this attack is made easier due to a GUI truncation issue that prevents the user from seeing the malicious extension when there is extra whitespace in the filename.

VendorProductVersions

n/a

n/a

affected
n/a

References

USN-275-1
vendor-advisory
x_refsource_UBUNTU
19902
third-party-advisory
x_refsource_SECUNIA
HPSBUX02122
vendor-advisory
x_refsource_HP
19941
third-party-advisory
x_refsource_SECUNIA
GLSA-200604-12
vendor-advisory
x_refsource_GENTOO
21622
third-party-advisory
x_refsource_SECUNIA
19862
third-party-advisory
x_refsource_SECUNIA
MDKSA-2006:075
vendor-advisory
x_refsource_MANDRIVA
DSA-1051
vendor-advisory
x_refsource_DEBIAN
USN-271-1
vendor-advisory
x_refsource_UBUNTU
GLSA-200604-18
vendor-advisory
x_refsource_GENTOO
19794
third-party-advisory
x_refsource_SECUNIA
oval:org.mitre.oval:def:1548
vdb-entry
signature
x_refsource_OVAL
19746
third-party-advisory
x_refsource_SECUNIA
21033
third-party-advisory
x_refsource_SECUNIA
102550
vendor-advisory
x_refsource_SUNALERT
19759
third-party-advisory
x_refsource_SECUNIA
SUSE-SA:2006:021
vendor-advisory
x_refsource_SUSE
ADV-2006-1356
vdb-entry
x_refsource_VUPEN
SSRT061158
vendor-advisory
x_refsource_HP
19863
third-party-advisory
x_refsource_SECUNIA
17516
vdb-entry
x_refsource_BID
228526
vendor-advisory
x_refsource_SUNALERT
19852
third-party-advisory
x_refsource_SECUNIA
19721
third-party-advisory
x_refsource_SECUNIA
19631
third-party-advisory
x_refsource_SECUNIA
MDKSA-2006:076
vendor-advisory
x_refsource_MANDRIVA
DSA-1046
vendor-advisory
x_refsource_DEBIAN
DSA-1044
vendor-advisory
x_refsource_DEBIAN

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now