CVE-2006-0296

critical

Description

The XULDocument.persist function in Mozilla, Firefox before 1.5.0.1, and SeaMonkey before 1.0 does not validate the attribute name, which allows remote attackers to execute arbitrary Javascript by injecting RDF data into the user's localstore.rdf file.

References

https://usn.ubuntu.com/276-1/

https://usn.ubuntu.com/275-1/

https://usn.ubuntu.com/271-1/

https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1493

https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11803

https://exchange.xforce.ibmcloud.com/vulnerabilities/24434

https://bugzilla.mozilla.org/show_bug.cgi?id=319847

http://www.vupen.com/english/advisories/2006/3749

http://www.vupen.com/english/advisories/2006/3391

http://www.vupen.com/english/advisories/2006/0413

http://www.us-cert.gov/cas/techalerts/TA06-038A.html

http://www.securityfocus.com/bid/16476

http://www.securityfocus.com/archive/1/446657/100/200/threaded

http://www.securityfocus.com/archive/1/438730/100/0/threaded

http://www.securityfocus.com/archive/1/425978/100/0/threaded

http://www.securityfocus.com/archive/1/425975/100/0/threaded

http://www.redhat.com/support/errata/RHSA-2006-0330.html

http://www.redhat.com/support/errata/RHSA-2006-0200.html

http://www.redhat.com/support/errata/RHSA-2006-0199.html

http://www.redhat.com/archives/fedora-announce-list/2006-February/msg00006.html

http://www.redhat.com/archives/fedora-announce-list/2006-February/msg00005.html

http://www.novell.com/linux/security/advisories/2006_04_25.html

http://www.mozilla.org/security/announce/2006/mfsa2006-05.html

http://www.mandriva.com/security/advisories?name=MDKSA-2006:078

http://www.mandriva.com/security/advisories?name=MDKSA-2006:037

http://www.mandriva.com/security/advisories?name=MDKSA-2006:036

http://www.kb.cert.org/vuls/id/592425

http://www.gentoo.org/security/en/glsa/glsa-200605-09.xml

http://www.gentoo.org/security/en/glsa/glsa-200604-18.xml

http://www.gentoo.org/security/en/glsa/glsa-200604-12.xml

http://www.debian.org/security/2006/dsa-1051

http://www.debian.org/security/2006/dsa-1046

http://www.debian.org/security/2006/dsa-1044

http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm

http://sunsolve.sun.com/search/document.do?assetkey=1-26-228526-1

http://sunsolve.sun.com/search/document.do?assetkey=1-26-102550-1

http://securitytracker.com/id?1015570

http://secunia.com/advisories/22065

http://secunia.com/advisories/21622

http://secunia.com/advisories/21033

http://secunia.com/advisories/20051

http://secunia.com/advisories/19950

http://secunia.com/advisories/19941

http://secunia.com/advisories/19902

http://secunia.com/advisories/19863

http://secunia.com/advisories/19862

http://secunia.com/advisories/19852

http://secunia.com/advisories/19823

http://secunia.com/advisories/19821

http://secunia.com/advisories/19780

http://secunia.com/advisories/19759

http://secunia.com/advisories/19746

http://secunia.com/advisories/19230

http://secunia.com/advisories/18709

http://secunia.com/advisories/18708

http://secunia.com/advisories/18706

http://secunia.com/advisories/18705

http://secunia.com/advisories/18704

http://secunia.com/advisories/18703

http://secunia.com/advisories/18700

Details

Source: Mitre, NVD

Published: 2006-02-02

Risk Information

CVSS v2

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:N

Severity: Medium

CVSS v3

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical