CVE-2006-4569
Description
The popup blocker in Mozilla Firefox before 1.5.0.7 opens the blocked popups display in the context of the Location bar instead of the subframe from which the popup originated, which might make it easier for remote user-assisted attackers to conduct cross-site scripting (XSS) attacks.
Risk Information
Base Score
6.1
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS Score
Exploitation Probability
2.727
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Multiple vulnerabilities affected in Mozilla Firefox (x64) 1.5.0.6 | Windows |
| Multiple vulnerabilities affected in Mozilla_Firefox 1.5.0.6 | Windows |
| Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 1.5.0.6 | Windows |
| Multiple Vulnerabilities are affected in Mozilla_Firefox 1.5.0.6 | Windows |
| Multiple vulnerabilities are fixed in Mozilla Firefox For Mac 1.5.0.7 | Mac |
Patch Details
Click to see the patches provided by ManageEngine for this CVE
| Patch ID | Patch Description |
|---|---|
| PATCH-343016 | Mozilla Firefox (x64) (132.0.2) |
| PATCH-343015 | Mozilla Firefox (132.0.2) |
| PATCH-613630 | Mozilla Firefox For Mac (147.0.4) |
References
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234