---
title: "CVE-2006-1731\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2006-1731?format=md
keywords: index, follow
---

# CVE-2006-1731

Publication date 14 April 2006

Last updated 17 July 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8,
Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 returns the Object
class prototype instead of the global window object when (1) .valueOf.call
or (2) .valueOf.apply are called without any arguments, which allows remote
attackers to conduct cross-site scripting (XSS) attacks.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| firefox | 7.04 feisty | Not affected |
| 6.10 edgy | Not affected |
| 6.06 LTS dapper | Fixed 1.5.dfsg+1.5.0.13~prepatch070731-0ubuntu1 |
| firefox-granparadiso | 7.04 feisty | Not in release |
| 6.10 edgy | Not in release |
| 6.06 LTS dapper | Not in release |
| lightning-sunbird | 7.04 feisty | Not in release |
| 6.10 edgy | Not in release |
| 6.06 LTS dapper | Not in release |
| midbrowser | 7.04 feisty | Not in release |
| 6.10 edgy | Not in release |
| 6.06 LTS dapper | Not in release |
| mozilla-thunderbird | 7.04 feisty | Fixed 1.5.0.13-0ubuntu0.7.04 |
| 6.10 edgy | Fixed 1.5.0.13-0ubuntu0.6.10 |
| 6.06 LTS dapper | Fixed 1.5.0.13-0ubuntu0.6.06 |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1731)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2006-1731)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2006-1731)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2006-1731)

### Related Ubuntu Security Notices (USN)

+ [USN-275-1](https://usn.ubuntu.com/USN-275-1)
+ Mozilla vulnerabilities
+ 28 April 2006

+ [USN-271-1](https://usn.ubuntu.com/USN-271-1)
+ Firefox vulnerabilities
+ 20 April 2006

+ [USN-276-1](https://usn.ubuntu.com/USN-276-1)
+ Thunderbird vulnerabilities
+ 3 May 2006

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2006-1731>
