4.3

CVE-2006-0496

Exploit
Cross-site scripting (XSS) vulnerability in Mozilla 1.7.12 and possibly earlier, Mozilla Firefox 1.0.7 and possibly earlier, and Netscape 8.1 and possibly earlier, allows remote attackers to inject arbitrary web script or HTML via the -moz-binding (Cascading Style Sheets) CSS property, which does not require that the style sheet have the same origin as the web page, as demonstrated by the compromise of a large number of LiveJournal accounts.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mozilla ≫ Firefox Version 1.0
Mozilla ≫ Firefox Version 1.0.1
Mozilla ≫ Firefox Version 1.0.2
Mozilla ≫ Firefox Version 1.0.3
Mozilla ≫ Firefox Version 1.0.4
Mozilla ≫ Firefox Version 1.0.5
Mozilla ≫ Firefox Version 1.0.6
Mozilla ≫ Firefox Version 1.0.7
Mozilla ≫ Mozilla Version 1.7
Mozilla ≫ Mozilla Version 1.7 Update alpha
Mozilla ≫ Mozilla Version 1.7 Update beta
Mozilla ≫ Mozilla Version 1.7 Update rc1
Mozilla ≫ Mozilla Version 1.7 Update rc2
Mozilla ≫ Mozilla Version 1.7 Update rc3
Mozilla ≫ Mozilla Version 1.7.1
Mozilla ≫ Mozilla Version 1.7.2
Mozilla ≫ Mozilla Version 1.7.3
Mozilla ≫ Mozilla Version 1.7.5
Mozilla ≫ Mozilla Version 1.7.6
Mozilla ≫ Mozilla Version 1.7.7
Mozilla ≫ Mozilla Version 1.7.8
Mozilla ≫ Mozilla Version 1.7.10
Mozilla ≫ Mozilla Version 1.7.11
Mozilla ≫ Mozilla Version 1.7.12
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.67% 0.841
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://community.livejournal.com/lj_dev/708069.html
http://marc.info/?l=full-disclosure&m=113847912709062&w=2
http://securitytracker.com/id?1015553
http://securitytracker.com/id?1015563
http://www.davidpashley.com/cgi/pyblosxom.cgi/computing/livejournal-mozilla-bug.html
http://www.osvdb.org/22924
http://www.securityfocus.com/bid/16427
Exploit
http://www.vupen.com/english/advisories/2006/0403
https://bugzilla.mozilla.org/show_bug.cgi?id=324253
https://exchange.xforce.ibmcloud.com/vulnerabilities/24427