CVE-2006-1731

Mozilla Suite <1.7.13 - XSS

Title source: llm

Description

Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 returns the Object class prototype instead of the global window object when (1) .valueOf.call or (2) .valueOf.apply are called without any arguments, which allows remote attackers to conduct cross-site scripting (XSS) attacks.

References (55)

... and 35 more

Scores

EPSS 0.0282
EPSS Percentile 86.0%

Classification

CWE
CWE-79
Status draft

Affected Products (30)

mozilla/firefox < 1.0.7
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/mozilla_suite < 1.7.12
mozilla/mozilla_suite
mozilla/mozilla_suite
mozilla/mozilla_suite
... and 15 more

Timeline

Published Apr 14, 2006
Tracked Since Feb 18, 2026