Cross-site scripting (XSS) vulnerability in Mozilla Firefox 1.5 before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 allows remote attackers to inject arbitrary web script or HTML via the XPCNativeWrapper(window).Function construct.
CVSS Details
- CVSS 3.1 Base Score: 7.1
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade thunderbird | Jul 30, 2024 | Jul 27, 2006 |
| Freebsd | — | Upgrade thunderbirdUpgrade linux-seamonkeyUpgrade seamonkeyUpgrade linux-firefoxUpgrade mozilla-thunderbirdUpgrade firefoxUpgrade linux-thunderbirdUpgrade linux-mozillaUpgrade linux-firefox-develUpgrade mozillaUpgrade linux-mozilla-devel | Dec 10, 2025 | Jul 27, 2006 |
| Gentoo Linux | — | Upgrade www-client/mozilla-firefox-bin.Upgrade mail-client/mozilla-thunderbird.Upgrade www-client/seamonkey.Upgrade www-client/mozilla-firefox.Upgrade mail-client/mozilla-thunderbird-bin. | Oct 30, 2017 | Jul 27, 2006 |
| Mfsa2006 54 | — | Upgrade to Mozilla Firefox version 1.5.0.5Upgrade to the latest version of Mozilla Firefox | Aug 1, 2006 | Jul 26, 2006 |
| Ubuntu | — | Upgrade mozilla-thunderbird-locale-deUpgrade mozilla-thunderbird-inspectorUpgrade mozilla-thunderbird-locale-nlUpgrade mozilla-thunderbird-locale-caUpgrade mozilla-thunderbird-locale-plUpgrade mozilla-thunderbird-locale-ukUpgrade mozilla-thunderbird-locale-itUpgrade mozilla-thunderbird-enigmailUpgrade mozilla-thunderbird-typeaheadfindUpgrade mozilla-thunderbirdUpgrade firefoxUpgrade mozilla-thunderbird-locale-fr | Nov 8, 2024 | Jul 27, 2006 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub