6.8

CVE-2006-6503

Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to bypass cross-site scripting (XSS) protection by changing the src attribute of an IMG element to a javascript: URI.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MozillaFirefox Version >= 1.5 < 1.5.0.9
MozillaFirefox Version >= 2.0 < 2.0.0.1
MozillaSeamonkey Version < 1.0.7
MozillaThunderbird Version < 1.5.0.9
DebianDebian Linux Version3.1
DebianDebian Linux Version4.0
CanonicalUbuntu Linux Version5.10
CanonicalUbuntu Linux Version6.06 SwEditionlts
CanonicalUbuntu Linux Version6.10
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 17.11% 0.949
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://www.securityfocus.com/bid/21668
Third Party Advisory
VDB Entry
http://www.us-cert.gov/cas/techalerts/TA06-354A.html
Third Party Advisory
US Government Resource
http://securitytracker.com/id?1017414
Third Party Advisory
VDB Entry
http://securitytracker.com/id?1017415
Third Party Advisory
VDB Entry
http://securitytracker.com/id?1017416
Third Party Advisory
VDB Entry
http://www.kb.cert.org/vuls/id/405092
Third Party Advisory
US Government Resource