Oval Definition:oval:org.mitre.oval:def:9167
Revision Date:2013-04-29Version:11
Title:Mozilla Firefox 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to inject arbitrary Javascript into other sites by (1) "using a modal alert to suspend an event handler while a new page is being loaded", (2) using eval(), and using certain variants involving (3) "new Script;" and (4) using window.__proto__ to extend eval, aka "cross-site JavaScript injection".
Description:Mozilla Firefox 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to inject arbitrary Javascript into other sites by (1) "using a modal alert to suspend an event handler while a new page is being loaded", (2) using eval(), and using certain variants involving (3) "new Script;" and (4) using window.__proto__ to extend eval, aka "cross-site JavaScript injection".
Family:unixClass:vulnerability
Status:ACCEPTEDReference(s):CVE-2006-1741
Platform(s):CentOS Linux 3
CentOS Linux 4
Oracle Linux 4
Red Hat Enterprise Linux 3
Red Hat Enterprise Linux 4
Product(s):
Definition Synopsis
  • OS Section: RHEL3, CentOS3
  • RHEL3 or CentOS3
  • The operating system installed on the system is Red Hat Enterprise Linux 3
  • OR CentOS Linux 3.x
  • AND Configuration section
  • mozilla-js-debugger is earlier than 37:1.7.13-1.1.3.1
  • OR mozilla is earlier than 37:1.7.13-1.1.3.1
  • OR mozilla-chat is earlier than 37:1.7.13-1.1.3.1
  • OR mozilla-mail is earlier than 37:1.7.13-1.1.3.1
  • OR mozilla-dom-inspector is earlier than 37:1.7.13-1.1.3.1
  • OR mozilla-devel is earlier than 37:1.7.13-1.1.3.1
  • OR mozilla-nss is earlier than 37:1.7.13-1.1.3.1
  • OR mozilla-nss-devel is earlier than 37:1.7.13-1.1.3.1
  • OR mozilla-nspr is earlier than 37:1.7.13-1.1.3.1
  • OR mozilla-nspr-devel is earlier than 37:1.7.13-1.1.3.1
  • OR OS Section: RHEL4, CentOS4, Oracle Linux 4
  • RHEL4, CentOS4 or Oracle Linux 4
  • The operating system installed on the system is Red Hat Enterprise Linux 4
  • OR CentOS Linux 4.x
  • OR Oracle Linux 4.x
  • AND Configuration section
  • mozilla-js-debugger is earlier than 37:1.7.13-1.4.1
  • OR devhelp-devel is earlier than 0:0.9.2-2.4.8
  • OR mozilla is earlier than 37:1.7.13-1.4.1
  • OR thunderbird is earlier than 0:1.0.8-1.4.1
  • OR mozilla-chat is earlier than 37:1.7.13-1.4.1
  • OR mozilla-mail is earlier than 37:1.7.13-1.4.1
  • OR mozilla-dom-inspector is earlier than 37:1.7.13-1.4.1
  • OR devhelp is earlier than 0:0.9.2-2.4.8
  • OR mozilla-nss is earlier than 37:1.7.13-1.4.1
  • OR mozilla-devel is earlier than 37:1.7.13-1.4.1
  • OR mozilla-nss-devel is earlier than 37:1.7.13-1.4.1
  • OR firefox is earlier than 0:1.0.8-1.4.1
  • OR mozilla-nspr is earlier than 37:1.7.13-1.4.1
  • OR mozilla-nspr-devel is earlier than 37:1.7.13-1.4.1
  • BACK