CVE-2006-1741

Source
https://nvd.nist.gov/vuln/detail/CVE-2006-1741
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2006-1741.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2006-1741
Related
Published
2006-04-14T10:02:00Z
Modified
2025-04-03T01:03:51Z
Downstream
Summary
[none]
Details

Mozilla Firefox 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to inject arbitrary Javascript into other sites by (1) "using a modal alert to suspend an event handler while a new page is being loaded", (2) using eval(), and using certain variants involving (3) "new Script;" and (4) using window.proto to extend eval, aka "cross-site JavaScript injection".

References

Affected packages

Debian:11 / thunderbird

Package

Name
thunderbird
Purl
pkg:deb/debian/thunderbird?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.5.0.2-1

Ecosystem specific

{
    "urgency": "low"
}

Debian:12 / thunderbird

Package

Name
thunderbird
Purl
pkg:deb/debian/thunderbird?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.5.0.2-1

Ecosystem specific

{
    "urgency": "low"
}

Debian:13 / thunderbird

Package

Name
thunderbird
Purl
pkg:deb/debian/thunderbird?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.5.0.2-1

Ecosystem specific

{
    "urgency": "low"
}