CVE-2006-1740

Mozilla Firefox 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to spoof secure site indicators such as the locked icon by opening the trusted site in a popup window, then changing the location to a malicious site.
References
Link Resource
ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.26/SCOSA-2006.26.txt
ftp://patches.sgi.com/support/free/security/advisories/20060404-01-U.asc
http://lists.suse.com/archive/suse-security-announce/2006-Apr/0003.html
http://secunia.com/advisories/19631
http://secunia.com/advisories/19696
http://secunia.com/advisories/19714
http://secunia.com/advisories/19721
http://secunia.com/advisories/19729
http://secunia.com/advisories/19746
http://secunia.com/advisories/19759
http://secunia.com/advisories/19794
http://secunia.com/advisories/19811
http://secunia.com/advisories/19852
http://secunia.com/advisories/19862
http://secunia.com/advisories/19863
http://secunia.com/advisories/19902
http://secunia.com/advisories/19941
http://secunia.com/advisories/21033
http://secunia.com/advisories/21622
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102550-1
http://sunsolve.sun.com/search/document.do?assetkey=1-26-228526-1
http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm
http://www.debian.org/security/2006/dsa-1044
http://www.debian.org/security/2006/dsa-1046
http://www.debian.org/security/2006/dsa-1051
http://www.gentoo.org/security/en/glsa/glsa-200604-12.xml
http://www.gentoo.org/security/en/glsa/glsa-200604-18.xml
http://www.mandriva.com/security/advisories?name=MDKSA-2006:075
http://www.mandriva.com/security/advisories?name=MDKSA-2006:076
http://www.mozilla.org/security/announce/2006/mfsa2006-12.html
http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00153.html
http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00154.html
http://www.redhat.com/support/errata/RHSA-2006-0328.html
http://www.redhat.com/support/errata/RHSA-2006-0329.html
http://www.securityfocus.com/archive/1/436296/100/0/threaded
http://www.securityfocus.com/archive/1/436338/100/0/threaded
http://www.securityfocus.com/archive/1/438730/100/0/threaded
http://www.securityfocus.com/archive/1/438730/100/0/threaded
http://www.securityfocus.com/bid/17516
http://www.vupen.com/english/advisories/2006/1356
https://bugzilla.mozilla.org/show_bug.cgi?id=271194
https://exchange.xforce.ibmcloud.com/vulnerabilities/25813
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10424
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1811
https://usn.ubuntu.com/271-1/
https://usn.ubuntu.com/275-1/
ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.26/SCOSA-2006.26.txt
ftp://patches.sgi.com/support/free/security/advisories/20060404-01-U.asc
http://lists.suse.com/archive/suse-security-announce/2006-Apr/0003.html
http://secunia.com/advisories/19631
http://secunia.com/advisories/19696
http://secunia.com/advisories/19714
http://secunia.com/advisories/19721
http://secunia.com/advisories/19729
http://secunia.com/advisories/19746
http://secunia.com/advisories/19759
http://secunia.com/advisories/19794
http://secunia.com/advisories/19811
http://secunia.com/advisories/19852
http://secunia.com/advisories/19862
http://secunia.com/advisories/19863
http://secunia.com/advisories/19902
http://secunia.com/advisories/19941
http://secunia.com/advisories/21033
http://secunia.com/advisories/21622
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102550-1
http://sunsolve.sun.com/search/document.do?assetkey=1-26-228526-1
http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm
http://www.debian.org/security/2006/dsa-1044
http://www.debian.org/security/2006/dsa-1046
http://www.debian.org/security/2006/dsa-1051
http://www.gentoo.org/security/en/glsa/glsa-200604-12.xml
http://www.gentoo.org/security/en/glsa/glsa-200604-18.xml
http://www.mandriva.com/security/advisories?name=MDKSA-2006:075
http://www.mandriva.com/security/advisories?name=MDKSA-2006:076
http://www.mozilla.org/security/announce/2006/mfsa2006-12.html
http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00153.html
http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00154.html
http://www.redhat.com/support/errata/RHSA-2006-0328.html
http://www.redhat.com/support/errata/RHSA-2006-0329.html
http://www.securityfocus.com/archive/1/436296/100/0/threaded
http://www.securityfocus.com/archive/1/436338/100/0/threaded
http://www.securityfocus.com/archive/1/438730/100/0/threaded
http://www.securityfocus.com/archive/1/438730/100/0/threaded
http://www.securityfocus.com/bid/17516
http://www.vupen.com/english/advisories/2006/1356
https://bugzilla.mozilla.org/show_bug.cgi?id=271194
https://exchange.xforce.ibmcloud.com/vulnerabilities/25813
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10424
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1811
https://usn.ubuntu.com/271-1/
https://usn.ubuntu.com/275-1/
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:1.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:1.0.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:1.0.2:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:1.0.3:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:1.0.4:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:1.0.5:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:1.0.6:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:1.5:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:1.5:beta1:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:1.5:beta2:*:*:*:*:*:*
cpe:2.3:a:mozilla:mozilla_suite:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:mozilla_suite:1.7.6:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:mozilla_suite:1.7.7:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:mozilla_suite:1.7.8:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:mozilla_suite:1.7.10:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:mozilla_suite:1.7.11:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:*:beta:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:1.0:*:alpha:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:1.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:1.0.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:1.0.2:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:1.0.3:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:1.0.4:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:1.0.5:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:1.0.5:beta:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:1.0.6:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:1.5:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:1.5:beta2:*:*:*:*:*:*

History

21 Nov 2024, 00:09

Type Values Removed Values Added
References () ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.26/SCOSA-2006.26.txt - () ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.26/SCOSA-2006.26.txt -
References () ftp://patches.sgi.com/support/free/security/advisories/20060404-01-U.asc - () ftp://patches.sgi.com/support/free/security/advisories/20060404-01-U.asc -
References () http://lists.suse.com/archive/suse-security-announce/2006-Apr/0003.html - () http://lists.suse.com/archive/suse-security-announce/2006-Apr/0003.html -
References () http://secunia.com/advisories/19631 - () http://secunia.com/advisories/19631 -
References () http://secunia.com/advisories/19696 - () http://secunia.com/advisories/19696 -
References () http://secunia.com/advisories/19714 - () http://secunia.com/advisories/19714 -
References () http://secunia.com/advisories/19721 - () http://secunia.com/advisories/19721 -
References () http://secunia.com/advisories/19729 - () http://secunia.com/advisories/19729 -
References () http://secunia.com/advisories/19746 - () http://secunia.com/advisories/19746 -
References () http://secunia.com/advisories/19759 - () http://secunia.com/advisories/19759 -
References () http://secunia.com/advisories/19794 - () http://secunia.com/advisories/19794 -
References () http://secunia.com/advisories/19811 - () http://secunia.com/advisories/19811 -
References () http://secunia.com/advisories/19852 - () http://secunia.com/advisories/19852 -
References () http://secunia.com/advisories/19862 - () http://secunia.com/advisories/19862 -
References () http://secunia.com/advisories/19863 - () http://secunia.com/advisories/19863 -
References () http://secunia.com/advisories/19902 - () http://secunia.com/advisories/19902 -
References () http://secunia.com/advisories/19941 - () http://secunia.com/advisories/19941 -
References () http://secunia.com/advisories/21033 - () http://secunia.com/advisories/21033 -
References () http://secunia.com/advisories/21622 - () http://secunia.com/advisories/21622 -
References () http://sunsolve.sun.com/search/document.do?assetkey=1-26-102550-1 - () http://sunsolve.sun.com/search/document.do?assetkey=1-26-102550-1 -
References () http://sunsolve.sun.com/search/document.do?assetkey=1-26-228526-1 - () http://sunsolve.sun.com/search/document.do?assetkey=1-26-228526-1 -
References () http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm - () http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm -
References () http://www.debian.org/security/2006/dsa-1044 - () http://www.debian.org/security/2006/dsa-1044 -
References () http://www.debian.org/security/2006/dsa-1046 - () http://www.debian.org/security/2006/dsa-1046 -
References () http://www.debian.org/security/2006/dsa-1051 - () http://www.debian.org/security/2006/dsa-1051 -
References () http://www.gentoo.org/security/en/glsa/glsa-200604-12.xml - () http://www.gentoo.org/security/en/glsa/glsa-200604-12.xml -
References () http://www.gentoo.org/security/en/glsa/glsa-200604-18.xml - () http://www.gentoo.org/security/en/glsa/glsa-200604-18.xml -
References () http://www.mandriva.com/security/advisories?name=MDKSA-2006:075 - () http://www.mandriva.com/security/advisories?name=MDKSA-2006:075 -
References () http://www.mandriva.com/security/advisories?name=MDKSA-2006:076 - () http://www.mandriva.com/security/advisories?name=MDKSA-2006:076 -
References () http://www.mozilla.org/security/announce/2006/mfsa2006-12.html - () http://www.mozilla.org/security/announce/2006/mfsa2006-12.html -
References () http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00153.html - () http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00153.html -
References () http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00154.html - () http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00154.html -
References () http://www.redhat.com/support/errata/RHSA-2006-0328.html - () http://www.redhat.com/support/errata/RHSA-2006-0328.html -
References () http://www.redhat.com/support/errata/RHSA-2006-0329.html - () http://www.redhat.com/support/errata/RHSA-2006-0329.html -
References () http://www.securityfocus.com/archive/1/436296/100/0/threaded - () http://www.securityfocus.com/archive/1/436296/100/0/threaded -
References () http://www.securityfocus.com/archive/1/436338/100/0/threaded - () http://www.securityfocus.com/archive/1/436338/100/0/threaded -
References () http://www.securityfocus.com/archive/1/438730/100/0/threaded - () http://www.securityfocus.com/archive/1/438730/100/0/threaded -
References () http://www.securityfocus.com/bid/17516 - () http://www.securityfocus.com/bid/17516 -
References () http://www.vupen.com/english/advisories/2006/1356 - () http://www.vupen.com/english/advisories/2006/1356 -
References () https://bugzilla.mozilla.org/show_bug.cgi?id=271194 - () https://bugzilla.mozilla.org/show_bug.cgi?id=271194 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/25813 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/25813 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10424 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10424 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1811 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1811 -
References () https://usn.ubuntu.com/271-1/ - () https://usn.ubuntu.com/271-1/ -
References () https://usn.ubuntu.com/275-1/ - () https://usn.ubuntu.com/275-1/ -

Information

Published : 2006-04-14 10:02

Updated : 2024-11-21 00:09


NVD link : CVE-2006-1740

Mitre link : CVE-2006-1740

CVE.ORG link : CVE-2006-1740


JSON object : View

Products Affected

mozilla

  • mozilla_suite
  • firefox
  • thunderbird
  • seamonkey