CVE Database
/

CVE-2006-1741

Back to search

CVE-2006-1741

Published: Apr 14, 2006

Modified: Aug 7, 2024

PUBLISHED

Description

Mozilla Firefox 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to inject arbitrary Javascript into other sites by (1) "using a modal alert to suspend an event handler while a new page is being loaded", (2) using eval(), and using certain variants involving (3) "new Script;" and (4) using window.__proto__ to extend eval, aka "cross-site JavaScript injection".

VendorProductVersions

n/a

n/a

affected
n/a

References

USN-275-1
vendor-advisory
x_refsource_UBUNTU
RHSA-2006:0330
vendor-advisory
x_refsource_REDHAT
19902
third-party-advisory
x_refsource_SECUNIA
USN-276-1
vendor-advisory
x_refsource_UBUNTU
HPSBUX02122
vendor-advisory
x_refsource_HP
19941
third-party-advisory
x_refsource_SECUNIA
19780
third-party-advisory
x_refsource_SECUNIA
RHSA-2006:0328
vendor-advisory
x_refsource_REDHAT
19821
third-party-advisory
x_refsource_SECUNIA
GLSA-200604-12
vendor-advisory
x_refsource_GENTOO
21622
third-party-advisory
x_refsource_SECUNIA
19862
third-party-advisory
x_refsource_SECUNIA
19823
third-party-advisory
x_refsource_SECUNIA
DSA-1051
vendor-advisory
x_refsource_DEBIAN
FEDORA-2006-410
vendor-advisory
x_refsource_FEDORA
USN-271-1
vendor-advisory
x_refsource_UBUNTU
19714
third-party-advisory
x_refsource_SECUNIA
RHSA-2006:0329
vendor-advisory
x_refsource_REDHAT
GLSA-200604-18
vendor-advisory
x_refsource_GENTOO
19811
third-party-advisory
x_refsource_SECUNIA
mozilla-eventhandler-xss(25806)
vdb-entry
x_refsource_XF
19746
third-party-advisory
x_refsource_SECUNIA
21033
third-party-advisory
x_refsource_SECUNIA
oval:org.mitre.oval:def:9167
vdb-entry
signature
x_refsource_OVAL
102550
vendor-advisory
x_refsource_SUNALERT
19696
third-party-advisory
x_refsource_SECUNIA
19759
third-party-advisory
x_refsource_SECUNIA
SUSE-SA:2006:021
vendor-advisory
x_refsource_SUSE
FLSA:189137-2
vendor-advisory
x_refsource_FEDORA
ADV-2006-1356
vdb-entry
x_refsource_VUPEN
oval:org.mitre.oval:def:1855
vdb-entry
signature
x_refsource_OVAL
SSRT061158
vendor-advisory
x_refsource_HP
MDKSA-2006:078
vendor-advisory
x_refsource_MANDRIVA
19729
third-party-advisory
x_refsource_SECUNIA
20051
third-party-advisory
x_refsource_SECUNIA
19863
third-party-advisory
x_refsource_SECUNIA
FLSA:189137-1
vendor-advisory
x_refsource_FEDORA
228526
vendor-advisory
x_refsource_SUNALERT
FEDORA-2006-411
vendor-advisory
x_refsource_FEDORA
19852
third-party-advisory
x_refsource_SECUNIA
19721
third-party-advisory
x_refsource_SECUNIA
SUSE-SA:2006:022
vendor-advisory
x_refsource_SUSE
GLSA-200605-09
vendor-advisory
x_refsource_GENTOO
19631
third-party-advisory
x_refsource_SECUNIA
19950
third-party-advisory
x_refsource_SECUNIA
MDKSA-2006:076
vendor-advisory
x_refsource_MANDRIVA
DSA-1046
vendor-advisory
x_refsource_DEBIAN
DSA-1044
vendor-advisory
x_refsource_DEBIAN

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now