CVE-2006-1731
Mozilla Suite <1.7.13 - XSS
Title source: llmDescription
Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 returns the Object class prototype instead of the global window object when (1) .valueOf.call or (2) .valueOf.apply are called without any arguments, which allows remote attackers to conduct cross-site scripting (XSS) attacks.
References (55)
... and 35 more
Scores
EPSS
0.0282
EPSS Percentile
86.0%
Classification
CWE
CWE-79
Status
draft
Affected Products (30)
mozilla/firefox
< 1.0.7
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/mozilla_suite
< 1.7.12
mozilla/mozilla_suite
mozilla/mozilla_suite
mozilla/mozilla_suite
... and 15 more
Timeline
Published
Apr 14, 2006
Tracked Since
Feb 18, 2026