CVE Vulnerabilities

CVE-2006-0299

Published: Feb 02, 2006 | Modified: Oct 19, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.4 MEDIUM
AV:N/AC:L/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

The E4X implementation in Mozilla Firefox before 1.5.0.1, Thunderbird 1.5 if running Javascript in mail, and SeaMonkey before 1.0 exposes the internal AnyName object to external interfaces, which allows multiple cooperating domains to exchange information in violation of the same origin restrictions.

Affected Software

Name Vendor Start Version End Version
Firefox Mozilla 1.5 (including) 1.5 (including)
Firefox Mozilla 1.5-beta1 (including) 1.5-beta1 (including)
Seamonkey Mozilla 1.0 (including) 1.0 (including)
Seamonkey Mozilla 1.0-beta (including) 1.0-beta (including)
Thunderbird Mozilla 1.5 (including) 1.5 (including)

References