CVE-2006-4561 Affecting mozilla package, versions [,1.5.0.6]


Severity

Recommended
0.0
high
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.97% (84th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-MOZILLA-2378112
  • published26 Jan 2022
  • disclosed6 Sept 2006
  • creditUnknown

Introduced: 6 Sep 2006

CVE-2006-4561  (opens in a new tab)

How to fix?

There is no fixed version for mozilla.

Overview

Mozilla Firefox 1.5.0.6 allows remote attackers to execute arbitrary JavaScript in the context of the browser's session with an arbitrary intranet web server, by hosting script on an Internet web server that can be made inaccessible by the attacker and that has a domain name under the attacker's control, which can force the browser to drop DNS pinning and perform a new DNS query for the domain name after the script is already running.

References

CVSS Scores

version 3.1