CVE-2006-4569

The popup blocker in Mozilla Firefox before 1.5.0.7 opens the "blocked popups" display in the context of the Location bar instead of the subframe from which the popup originated, which might make it easier for remote user-assisted attackers to conduct cross-site scripting (XSS) attacks.
References
Link Resource
http://secunia.com/advisories/21949 Patch Vendor Advisory
http://secunia.com/advisories/21950
http://secunia.com/advisories/22001
http://secunia.com/advisories/22025
http://secunia.com/advisories/22056
http://secunia.com/advisories/22066
http://secunia.com/advisories/22195
http://secunia.com/advisories/22210
http://secunia.com/advisories/22422
http://secunia.com/advisories/24711
http://security.gentoo.org/glsa/glsa-200609-19.xml
http://securitytracker.com/id?1016849
http://support.avaya.com/elmodocs2/security/ASA-2006-224.htm
http://www.mandriva.com/security/advisories?name=MDKSA-2006:168
http://www.mozilla.org/security/announce/2006/mfsa2006-62.html Vendor Advisory
http://www.novell.com/linux/security/advisories/2006_54_mozilla.html
http://www.redhat.com/support/errata/RHSA-2006-0675.html
http://www.securityfocus.com/archive/1/446140/100/0/threaded
http://www.securityfocus.com/bid/20042
http://www.ubuntu.com/usn/usn-351-1
http://www.ubuntu.com/usn/usn-354-1
http://www.vupen.com/english/advisories/2006/3748
http://www.vupen.com/english/advisories/2007/1198
http://www.vupen.com/english/advisories/2008/0083
http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00771742
http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00771742
https://exchange.xforce.ibmcloud.com/vulnerabilities/28957
https://issues.rpath.com/browse/RPL-640
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10650
http://secunia.com/advisories/21949 Patch Vendor Advisory
http://secunia.com/advisories/21950
http://secunia.com/advisories/22001
http://secunia.com/advisories/22025
http://secunia.com/advisories/22056
http://secunia.com/advisories/22066
http://secunia.com/advisories/22195
http://secunia.com/advisories/22210
http://secunia.com/advisories/22422
http://secunia.com/advisories/24711
http://security.gentoo.org/glsa/glsa-200609-19.xml
http://securitytracker.com/id?1016849
http://support.avaya.com/elmodocs2/security/ASA-2006-224.htm
http://www.mandriva.com/security/advisories?name=MDKSA-2006:168
http://www.mozilla.org/security/announce/2006/mfsa2006-62.html Vendor Advisory
http://www.novell.com/linux/security/advisories/2006_54_mozilla.html
http://www.redhat.com/support/errata/RHSA-2006-0675.html
http://www.securityfocus.com/archive/1/446140/100/0/threaded
http://www.securityfocus.com/bid/20042
http://www.ubuntu.com/usn/usn-351-1
http://www.ubuntu.com/usn/usn-354-1
http://www.vupen.com/english/advisories/2006/3748
http://www.vupen.com/english/advisories/2007/1198
http://www.vupen.com/english/advisories/2008/0083
http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00771742
http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00771742
https://exchange.xforce.ibmcloud.com/vulnerabilities/28957
https://issues.rpath.com/browse/RPL-640
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10650
Configurations

Configuration 1 (hide)

cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*

History

21 Nov 2024, 00:16

Type Values Removed Values Added
References () http://secunia.com/advisories/21949 - Patch, Vendor Advisory () http://secunia.com/advisories/21949 - Patch, Vendor Advisory
References () http://secunia.com/advisories/21950 - () http://secunia.com/advisories/21950 -
References () http://secunia.com/advisories/22001 - () http://secunia.com/advisories/22001 -
References () http://secunia.com/advisories/22025 - () http://secunia.com/advisories/22025 -
References () http://secunia.com/advisories/22056 - () http://secunia.com/advisories/22056 -
References () http://secunia.com/advisories/22066 - () http://secunia.com/advisories/22066 -
References () http://secunia.com/advisories/22195 - () http://secunia.com/advisories/22195 -
References () http://secunia.com/advisories/22210 - () http://secunia.com/advisories/22210 -
References () http://secunia.com/advisories/22422 - () http://secunia.com/advisories/22422 -
References () http://secunia.com/advisories/24711 - () http://secunia.com/advisories/24711 -
References () http://security.gentoo.org/glsa/glsa-200609-19.xml - () http://security.gentoo.org/glsa/glsa-200609-19.xml -
References () http://securitytracker.com/id?1016849 - () http://securitytracker.com/id?1016849 -
References () http://support.avaya.com/elmodocs2/security/ASA-2006-224.htm - () http://support.avaya.com/elmodocs2/security/ASA-2006-224.htm -
References () http://www.mandriva.com/security/advisories?name=MDKSA-2006:168 - () http://www.mandriva.com/security/advisories?name=MDKSA-2006:168 -
References () http://www.mozilla.org/security/announce/2006/mfsa2006-62.html - Vendor Advisory () http://www.mozilla.org/security/announce/2006/mfsa2006-62.html - Vendor Advisory
References () http://www.novell.com/linux/security/advisories/2006_54_mozilla.html - () http://www.novell.com/linux/security/advisories/2006_54_mozilla.html -
References () http://www.redhat.com/support/errata/RHSA-2006-0675.html - () http://www.redhat.com/support/errata/RHSA-2006-0675.html -
References () http://www.securityfocus.com/archive/1/446140/100/0/threaded - () http://www.securityfocus.com/archive/1/446140/100/0/threaded -
References () http://www.securityfocus.com/bid/20042 - () http://www.securityfocus.com/bid/20042 -
References () http://www.ubuntu.com/usn/usn-351-1 - () http://www.ubuntu.com/usn/usn-351-1 -
References () http://www.ubuntu.com/usn/usn-354-1 - () http://www.ubuntu.com/usn/usn-354-1 -
References () http://www.vupen.com/english/advisories/2006/3748 - () http://www.vupen.com/english/advisories/2006/3748 -
References () http://www.vupen.com/english/advisories/2007/1198 - () http://www.vupen.com/english/advisories/2007/1198 -
References () http://www.vupen.com/english/advisories/2008/0083 - () http://www.vupen.com/english/advisories/2008/0083 -
References () http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00771742 - () http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00771742 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/28957 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/28957 -
References () https://issues.rpath.com/browse/RPL-640 - () https://issues.rpath.com/browse/RPL-640 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10650 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10650 -

Information

Published : 2006-09-15 19:07

Updated : 2024-11-21 00:16


NVD link : CVE-2006-4569

Mitre link : CVE-2006-4569

CVE.ORG link : CVE-2006-4569


JSON object : View

Products Affected

mozilla

  • firefox