CVE-2006-0299

Mozilla Firefox <1.5.0.1, Thunderbird <1.5, SeaMonkey <1.0 - Info D...

Title source: llm
STIX 2.1

Description

The E4X implementation in Mozilla Firefox before 1.5.0.1, Thunderbird 1.5 if running Javascript in mail, and SeaMonkey before 1.0 exposes the internal "AnyName" object to external interfaces, which allows multiple cooperating domains to exchange information in violation of the same origin restrictions.

References (12)

Core 12
Core References
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1625
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/24437
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/18704
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/3749
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/16476
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/0413
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1015570
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/18700
Third Party Advisory, VDB Entry vendor-advisory x_refsource_hp
http://www.securityfocus.com/archive/1/446657/100/200/threaded
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/22065
Issue Tracking x_refsource_confirm
https://bugzilla.mozilla.org/show_bug.cgi?id=322312

Scores

EPSS 0.0197
EPSS Percentile 78.3%

Details

Status published
Products (3)
mozilla/firefox 1.5 (2 CPE variants)
mozilla/seamonkey 1.0 (2 CPE variants)
mozilla/thunderbird 1.5
Published Feb 02, 2006
Tracked Since Feb 18, 2026