FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2006-4570

This CVE name corresponds to:

Entered Topic
2006-09-15 mozilla -- multiple vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2006-4570
Phase Assigned(20060906)

Description

Mozilla Thunderbird before 1.5.0.7 and SeaMonkey before 1.0.5, with "Load Images" enabled, allows remote user-assisted attackers to bypass settings that disable JavaScript via a remote XBL file in a message that is loaded when the user views, forwards, or replies to the original message.

References

Source Reference
CONFIRM http://www.mozilla.org/security/announce/2006/mfsa2006-63.html
DEBIAN DSA-1191
DEBIAN DSA-1192
GENTOO GLSA-200610-01
GENTOO GLSA-200610-04
MANDRIVA MDKSA-2006:169
REDHAT RHSA-2006:0676
REDHAT RHSA-2006:0677
SGI 20060901-01-P
SUSE SUSE-SA:2006:054
UBUNTU USN-350-1
UBUNTU USN-352-1
UBUNTU USN-361-1
BID 20042
OVAL oval:org.mitre.oval:def:10892
SECTRACK 1016866
SECTRACK 1016867
SECUNIA 21915
SECUNIA 21916
SECUNIA 21939
SECUNIA 21940
SECUNIA 22036
SECUNIA 22055
SECUNIA 22074
SECUNIA 22088
SECUNIA 22247
SECUNIA 22274
SECUNIA 22299
SECUNIA 22342
SECUNIA 22391
SECUNIA 22056
XF thunderbird-seamonkey-xbl-code-execution(28962)