Vulnerability Database

289,599

Total vulnerabilities in the database

CVE-2006-0296

The XULDocument.persist function in Mozilla, Firefox before 1.5.0.1, and SeaMonkey before 1.0 does not validate the attribute name, which allows remote attackers to execute arbitrary Javascript by injecting RDF data into the user's localstore.rdf file.

  • Published: Feb 2, 2006
  • Updated: Apr 13, 2023
  • CVE: CVE-2006-0296
  • Severity: Medium
  • Exploit:

CVSS v2:

  • Severity: Medium
  • Score: 5
  • AV:N/AC:L/Au:N/C:N/I:P/A:N

No CWE or OWASP classifications available.

Software From Fixed in
mozilla / firefox 0.8 0.8.x
mozilla / firefox 1.0.2 1.0.2.x
mozilla / seamonkey 1.0-beta 1.0-beta.x
mozilla / firefox 1.5-beta1 1.5-beta1.x
mozilla / firefox 1.5 1.5.x
mozilla / firefox 0.9.1 0.9.1.x
mozilla / firefox 1.0.4 1.0.4.x
mozilla / firefox 1.0.7 1.0.7.x
mozilla / firefox 0.10.1 0.10.1.x
mozilla / firefox 0.9 0.9.x
mozilla / seamonkey 1.0 1.0.x
mozilla / firefox 1.0 1.0.x
mozilla / firefox 1.0.1 1.0.1.x
mozilla / firefox 1.0.6 1.0.6.x
mozilla / firefox 1.0.3 1.0.3.x
mozilla / firefox 0.9.3 0.9.3.x
mozilla / firefox 0.9.2 0.9.2.x
mozilla / firefox 0.9-rc 0.9-rc.x
mozilla / firefox 0.10 0.10.x
mozilla / firefox 1.0.5 1.0.5.x