// For flags

CVE-2006-0496

Mozilla Firefox 1.0/1.5 XBL - MOZ-BINDING Property Cross-Domain Scripting

Severity Score

4.3
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

2
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Cross-site scripting (XSS) vulnerability in Mozilla 1.7.12 and possibly earlier, Mozilla Firefox 1.0.7 and possibly earlier, and Netscape 8.1 and possibly earlier, allows remote attackers to inject arbitrary web script or HTML via the -moz-binding (Cascading Style Sheets) CSS property, which does not require that the style sheet have the same origin as the web page, as demonstrated by the compromise of a large number of LiveJournal accounts.

Vulnerabilidad de XSS en Mozilla 1.7.12 y posiblemente versiones anteriores, Mozilla Firefox 1.0.7 y posiblemente versiones anteriores y Netscape 8.1 y posiblemente versiones anteriores, permite a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarios a través de propiedad CSS (Cascading Style Sheets) -moz-binding, lo que no requiere que la hoja de estilos tenga el mismo origen que la página web, como es demostrado por el compromiso de un gran número de cuentas de LiveJournal.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
None
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2006-01-30 First Exploit
  • 2006-01-31 CVE Reserved
  • 2006-02-01 CVE Published
  • 2024-05-23 EPSS Updated
  • 2024-08-07 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Mozilla
Search vendor "Mozilla"
Firefox
Search vendor "Mozilla" for product "Firefox"
1.0
Search vendor "Mozilla" for product "Firefox" and version "1.0"
-
Affected
Mozilla
Search vendor "Mozilla"
Firefox
Search vendor "Mozilla" for product "Firefox"
1.0.1
Search vendor "Mozilla" for product "Firefox" and version "1.0.1"
-
Affected
Mozilla
Search vendor "Mozilla"
Firefox
Search vendor "Mozilla" for product "Firefox"
1.0.2
Search vendor "Mozilla" for product "Firefox" and version "1.0.2"
-
Affected
Mozilla
Search vendor "Mozilla"
Firefox
Search vendor "Mozilla" for product "Firefox"
1.0.3
Search vendor "Mozilla" for product "Firefox" and version "1.0.3"
-
Affected
Mozilla
Search vendor "Mozilla"
Firefox
Search vendor "Mozilla" for product "Firefox"
1.0.4
Search vendor "Mozilla" for product "Firefox" and version "1.0.4"
-
Affected
Mozilla
Search vendor "Mozilla"
Firefox
Search vendor "Mozilla" for product "Firefox"
1.0.5
Search vendor "Mozilla" for product "Firefox" and version "1.0.5"
-
Affected
Mozilla
Search vendor "Mozilla"
Firefox
Search vendor "Mozilla" for product "Firefox"
1.0.6
Search vendor "Mozilla" for product "Firefox" and version "1.0.6"
-
Affected
Mozilla
Search vendor "Mozilla"
Firefox
Search vendor "Mozilla" for product "Firefox"
1.0.7
Search vendor "Mozilla" for product "Firefox" and version "1.0.7"
-
Affected
Mozilla
Search vendor "Mozilla"
Mozilla
Search vendor "Mozilla" for product "Mozilla"
1.7
Search vendor "Mozilla" for product "Mozilla" and version "1.7"
-
Affected
Mozilla
Search vendor "Mozilla"
Mozilla
Search vendor "Mozilla" for product "Mozilla"
1.7
Search vendor "Mozilla" for product "Mozilla" and version "1.7"
alpha
Affected
Mozilla
Search vendor "Mozilla"
Mozilla
Search vendor "Mozilla" for product "Mozilla"
1.7
Search vendor "Mozilla" for product "Mozilla" and version "1.7"
beta
Affected
Mozilla
Search vendor "Mozilla"
Mozilla
Search vendor "Mozilla" for product "Mozilla"
1.7
Search vendor "Mozilla" for product "Mozilla" and version "1.7"
rc1
Affected
Mozilla
Search vendor "Mozilla"
Mozilla
Search vendor "Mozilla" for product "Mozilla"
1.7
Search vendor "Mozilla" for product "Mozilla" and version "1.7"
rc2
Affected
Mozilla
Search vendor "Mozilla"
Mozilla
Search vendor "Mozilla" for product "Mozilla"
1.7
Search vendor "Mozilla" for product "Mozilla" and version "1.7"
rc3
Affected
Mozilla
Search vendor "Mozilla"
Mozilla
Search vendor "Mozilla" for product "Mozilla"
1.7.1
Search vendor "Mozilla" for product "Mozilla" and version "1.7.1"
-
Affected
Mozilla
Search vendor "Mozilla"
Mozilla
Search vendor "Mozilla" for product "Mozilla"
1.7.2
Search vendor "Mozilla" for product "Mozilla" and version "1.7.2"
-
Affected
Mozilla
Search vendor "Mozilla"
Mozilla
Search vendor "Mozilla" for product "Mozilla"
1.7.3
Search vendor "Mozilla" for product "Mozilla" and version "1.7.3"
-
Affected
Mozilla
Search vendor "Mozilla"
Mozilla
Search vendor "Mozilla" for product "Mozilla"
1.7.5
Search vendor "Mozilla" for product "Mozilla" and version "1.7.5"
-
Affected
Mozilla
Search vendor "Mozilla"
Mozilla
Search vendor "Mozilla" for product "Mozilla"
1.7.6
Search vendor "Mozilla" for product "Mozilla" and version "1.7.6"
-
Affected
Mozilla
Search vendor "Mozilla"
Mozilla
Search vendor "Mozilla" for product "Mozilla"
1.7.7
Search vendor "Mozilla" for product "Mozilla" and version "1.7.7"
-
Affected
Mozilla
Search vendor "Mozilla"
Mozilla
Search vendor "Mozilla" for product "Mozilla"
1.7.8
Search vendor "Mozilla" for product "Mozilla" and version "1.7.8"
-
Affected
Mozilla
Search vendor "Mozilla"
Mozilla
Search vendor "Mozilla" for product "Mozilla"
1.7.10
Search vendor "Mozilla" for product "Mozilla" and version "1.7.10"
-
Affected
Mozilla
Search vendor "Mozilla"
Mozilla
Search vendor "Mozilla" for product "Mozilla"
1.7.11
Search vendor "Mozilla" for product "Mozilla" and version "1.7.11"
-
Affected
Mozilla
Search vendor "Mozilla"
Mozilla
Search vendor "Mozilla" for product "Mozilla"
1.7.12
Search vendor "Mozilla" for product "Mozilla" and version "1.7.12"
-
Affected