6.4

CVE-2006-0299

The E4X implementation in Mozilla Firefox before 1.5.0.1, Thunderbird 1.5 if running Javascript in mail, and SeaMonkey before 1.0 exposes the internal "AnyName" object to external interfaces, which allows multiple cooperating domains to exchange information in violation of the same origin restrictions.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mozilla ≫ Firefox Version 1.5
Mozilla ≫ Firefox Version 1.5 Update beta1
Mozilla ≫ Seamonkey Version 1.0 Edition alpha
Mozilla ≫ Seamonkey Version 1.0 Update beta
Mozilla ≫ Thunderbird Version 1.5
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.02% 0.789
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.4 10 4.9
AV:N/AC:L/Au:N/C:P/I:P/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/18700
http://secunia.com/advisories/18704
http://www.securityfocus.com/bid/16476
http://www.vupen.com/english/advisories/2006/0413
http://secunia.com/advisories/22065
http://securitytracker.com/id?1015570
http://www.securityfocus.com/archive/1/446657/100/200/threaded
http://www.vupen.com/english/advisories/2006/3749
http://www.mozilla.org/security/announce/2006/mfsa2006-08.html
https://bugzilla.mozilla.org/show_bug.cgi?id=322312
https://exchange.xforce.ibmcloud.com/vulnerabilities/24437
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1625