Vulnerability Database

289,697

Total vulnerabilities in the database

CVE-2006-2783

Mozilla Firefox and Thunderbird before 1.5.0.4 strip the Unicode Byte-order-Mark (BOM) from a UTF-8 page before the page is passed to the parser, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a BOM sequence in the middle of a dangerous tag such as SCRIPT.

  • Published: Jun 2, 2006
  • Updated: Apr 13, 2023
  • CVE: CVE-2006-2783
  • Severity: Low
  • Exploit:

CVSS v2:

  • Severity: Low
  • Score: 4.3
  • AV:N/AC:M/Au:N/C:N/I:P/A:N
Software From Fixed in
mozilla / firefox - 1.5.0.3.x
mozilla / thunderbird - 1.5.0.3.x