---
title: "CVE-2006-0496\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2006-0496?format=md
keywords: index, follow
---

# CVE-2006-0496

Publication date 1 February 2006

Last updated 17 July 2025

---

Ubuntu priority

**Negligible**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

Cross-site scripting (XSS) vulnerability in Mozilla 1.7.12 and possibly
earlier, Mozilla Firefox 1.0.7 and possibly earlier, and Netscape 8.1 and
possibly earlier, allows remote attackers to inject arbitrary web script or
HTML via the -moz-binding (Cascading Style Sheets) CSS property, which does
not require that the style sheet have the same origin as the web page, as
demonstrated by the compromise of a large number of LiveJournal accounts.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| firefox | 7.04 feisty | Ignored end of life |
| 6.10 edgy | Ignored end of life |
| 6.06 LTS dapper | Ignored end of life |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0496)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2006-0496)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2006-0496)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2006-0496)

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2006-0496>
