CVE Vulnerabilities

CVE-2006-0299

Published: Feb 02, 2006 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.4 MEDIUM
AV:N/AC:L/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The E4X implementation in Mozilla Firefox before 1.5.0.1, Thunderbird 1.5 if running Javascript in mail, and SeaMonkey before 1.0 exposes the internal AnyName object to external interfaces, which allows multiple cooperating domains to exchange information in violation of the same origin restrictions.

Affected Software

NameVendorStart VersionEnd Version
FirefoxMozilla1.5 (including)1.5 (including)
FirefoxMozilla1.5-beta1 (including)1.5-beta1 (including)
SeamonkeyMozilla1.0 (including)1.0 (including)
SeamonkeyMozilla1.0-beta (including)1.0-beta (including)
ThunderbirdMozilla1.5 (including)1.5 (including)
FirefoxUbuntudapper*
FirefoxUbuntuedgy*
FirefoxUbuntufeisty*
Firefox-granparadisoUbuntudevel*
Lightning-sunbirdUbuntudevel*
MidbrowserUbuntudevel*
Mozilla-thunderbirdUbuntudapper*
Mozilla-thunderbirdUbuntuedgy*
Mozilla-thunderbirdUbuntufeisty*

References