VDB

DEBIAN-CVE-2006-0296

DEBIAN-CVE-2006-0296 PUBLISHED CVSS 9.300000190734863 CRITICAL

The XULDocument.persist function in Mozilla, Firefox before 1.5.0.1, and SeaMonkey before 1.0 does not validate the attribute name, which allows remote attackers to execute arbitrary Javascript by injecting RDF data into the user's localstore.rdf file.

Risk Scores

CVSS v4.0
9.300000190734863
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected Products

VendorProductVersions
Debian:11thunderbird0, 0, 0
Debian:13thunderbird0, 0, 0
Debian:12thunderbird0, 0, 0
Debian:14thunderbird0, 0, 0

Timeline

  • Feb 2, 2006 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›