CVE-2006-1725
Mozilla Firefox 1.5 before 1.5.0.2 and SeaMonkey before 1.0.1 causes certain windows to become translucent due to an interaction between XUL content windows and the history mechanism, which might allow user-assisted remote attackers to trick users into…
Does this matter?
Lower severity and a low EPSS score (2.23%). Track it; it rarely justifies an emergency change on its own.
Description
Mozilla Firefox 1.5 before 1.5.0.2 and SeaMonkey before 1.0.1 causes certain windows to become translucent due to an interaction between XUL content windows and the history mechanism, which might allow user-assisted remote attackers to trick users into executing arbitrary code.
- CVSS 2.0
- 2.6 LOWAV:N/AC:H/Au:N/C:N/I:P/A:N
- EPSS
- 2.23% probability · 82th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- mozilla/firefox · mozilla/seamonkey
- Source
- secalert@redhat.com
References
- http://secunia.com/advisories/19631Third Party Advisory
- http://secunia.com/advisories/19649Third Party Advisory, Vendor Advisory
- http://secunia.com/advisories/22066Third Party Advisory
- http://www.mozilla.org/security/announce/2006/mfsa2006-29.htmlVendor Advisory
- http://www.securityfocus.com/archive/1/446658/100/200/threaded
- http://www.securityfocus.com/bid/17516Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2006/1356Permissions Required, Third Party Advisory
- http://www.vupen.com/english/advisories/2006/3748Permissions Required, Third Party Advisory
- http://www.vupen.com/english/advisories/2008/0083Permissions Required, Third Party Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=327014Exploit, Issue Tracking, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25827Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1471Third Party Advisory
- http://secunia.com/advisories/19631Third Party Advisory
- http://secunia.com/advisories/19649Third Party Advisory, Vendor Advisory
- http://secunia.com/advisories/22066Third Party Advisory
- http://www.mozilla.org/security/announce/2006/mfsa2006-29.htmlVendor Advisory
- http://www.securityfocus.com/archive/1/446658/100/200/threaded
- http://www.securityfocus.com/bid/17516Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2006/1356Permissions Required, Third Party Advisory
- http://www.vupen.com/english/advisories/2006/3748Permissions Required, Third Party Advisory
- http://www.vupen.com/english/advisories/2008/0083Permissions Required, Third Party Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=327014Exploit, Issue Tracking, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25827Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1471Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.