CVE-2006-0296
Last modified
CVE-2006-0296 is a vulnerability of currently unknown severity. The XULDocument.persist function in Mozilla, Firefox before 1.5.0.1, and SeaMonkey before 1.0 does not validate the attribute name, which allows remote attackers to execute arbitrary Javascript by injecting RDF data into the user's localstore.rdf file.. EPSS estimates a 4.04% chance of exploitation in the next 30 days.
Description
The XULDocument.persist function in Mozilla, Firefox before 1.5.0.1, and SeaMonkey before 1.0 does not validate the attribute name, which allows remote attackers to execute arbitrary Javascript by injecting RDF data into the user's localstore.rdf file.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox | 0.8 |
| Mozilla | Firefox | 0.9 |
| Mozilla | Firefox | 0.9.1 |
| Mozilla | Firefox | 0.9.2 |
| Mozilla | Firefox | 0.9.3 |
| Mozilla | Firefox | 0.10 |
| Mozilla | Firefox | 0.10.1 |
| Mozilla | Firefox | 1.0 |
| Mozilla | Firefox | 1.0.1 |
| Mozilla | Firefox | 1.0.2 |
| Mozilla | Firefox | 1.0.3 |
| Mozilla | Firefox | 1.0.4 |
| Mozilla | Firefox | 1.0.5 |
| Mozilla | Firefox | 1.0.6 |
| Mozilla | Firefox | 1.0.7 |
| Mozilla | Firefox | 1.5 |
| Mozilla | Seamonkey | 1.0 |
References
- http://www.kb.cert.org/vuls/id/592425US Government Resource
- http://www.redhat.com/support/errata/RHSA-2006-0199.htmlVendor Advisory
- http://www.redhat.com/support/errata/RHSA-2006-0200.htmlVendor Advisory
- http://www.us-cert.gov/cas/techalerts/TA06-038A.htmlUS Government Resource
- http://www.kb.cert.org/vuls/id/592425US Government Resource
- http://www.redhat.com/support/errata/RHSA-2006-0199.htmlVendor Advisory
- http://www.redhat.com/support/errata/RHSA-2006-0200.htmlVendor Advisory
- http://www.us-cert.gov/cas/techalerts/TA06-038A.htmlUS Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2006-0296?
How severe is CVE-2006-0296?
How do I fix CVE-2006-0296?
Are you affected by CVE-2006-0296?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
