CVE-2006-0299
Mozilla Firefox <1.5.0.1, Thunderbird <1.5, SeaMonkey <1.0 - Info D...
Title source: llmDescription
The E4X implementation in Mozilla Firefox before 1.5.0.1, Thunderbird 1.5 if running Javascript in mail, and SeaMonkey before 1.0 exposes the internal "AnyName" object to external interfaces, which allows multiple cooperating domains to exchange information in violation of the same origin restrictions.
References (12)
Core 12
Core References
Third Party Advisory, VDB Entry vdb-entry
signature
x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1625
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/24437
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/18704
Third Party Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2006/3749
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/16476
Third Party Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2006/0413
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://securitytracker.com/id?1015570
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/18700
Third Party Advisory, VDB Entry vendor-advisory
x_refsource_hp
http://www.securityfocus.com/archive/1/446657/100/200/threaded
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/22065
Issue Tracking x_refsource_confirm
https://bugzilla.mozilla.org/show_bug.cgi?id=322312
Various Sources x_refsource_confirm
http://www.mozilla.org/security/announce/2006/mfsa2006-08.html
Scores
EPSS
0.0197
EPSS Percentile
78.3%
Details
Status
published
Products (3)
mozilla/firefox
1.5 (2 CPE variants)
mozilla/seamonkey
1.0 (2 CPE variants)
mozilla/thunderbird
1.5
Published
Feb 02, 2006
Tracked Since
Feb 18, 2026