4.3

CVE-2006-1729

Mozilla Firefox 1.x before 1.5.0.2 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0.1 allows remote attackers to read arbitrary files by (1) inserting the target filename into a text box, then turning that box into a file upload control, or (2) changing the type of the input control that is associated with an event handler.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MozillaFirefox Version >= 1.0 < 1.0.8
MozillaFirefox Version >= 1.5 < 1.5.0.2
MozillaMozilla Suite Version < 1.7.13
MozillaSeamonkey Version < 1.0.1
CanonicalUbuntu Linux Version4.10
CanonicalUbuntu Linux Version5.04
CanonicalUbuntu Linux Version5.10
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.82% 0.821
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:P/I:N/A:N
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://www.vupen.com/english/advisories/2006/3391
Third Party Advisory
Permissions Required
https://usn.ubuntu.com/271-1/
Third Party Advisory
https://usn.ubuntu.com/275-1/
Third Party Advisory
http://www.securityfocus.com/bid/17516
Third Party Advisory
VDB Entry
http://www.vupen.com/english/advisories/2006/1356
Third Party Advisory
Permissions Required
http://www.vupen.com/english/advisories/2006/3748
Third Party Advisory
Permissions Required
http://www.vupen.com/english/advisories/2008/0083
Third Party Advisory
Permissions Required