CVE-2006-6585

Mozilla Firefox <3.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

The Extensions manager in Mozilla Firefox 2.0 does not properly populate the list of local extensions, which allows attackers to construct an extension that hides itself by finding its name in the list and then calling RemoveElement, as demonstrated by the FFsniFF extension. NOTE: it was later reported that 3.0 is also affected.

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/454058/100/0/threaded
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/493585/100/0/threaded
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/2046

Scores

EPSS 0.0104
EPSS Percentile 60.3%

Details

Status published
Products (2)
mozilla/firefox 2.0
mozilla/firefox 3.0
Published Dec 15, 2006
Tracked Since Feb 18, 2026