CVE-2006-2783
Publication date 2 June 2006
Last updated 24 July 2024
Ubuntu priority
Mozilla Firefox and Thunderbird before 1.5.0.4 strip the Unicode Byte-order-Mark (BOM) from a UTF-8 page before the page is passed to the parser, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a BOM sequence in the middle of a dangerous tag such as SCRIPT.
Status
Package | Ubuntu Release | Status |
---|---|---|
firefox | ||
firefox-granparadiso | ||
lightning-sunbird | ||
midbrowser | ||
mozilla-thunderbird | ||
xulrunner | ||
References
Related Ubuntu Security Notices (USN)
- USN-323-1
- mozilla vulnerabilities
- 26 July 2006
- USN-297-1
- Thunderbird vulnerabilities
- 14 June 2006
- USN-297-3
- Thunderbird vulnerabilities
- 26 July 2006
- USN-296-2
- Firefox vulnerabilities
- 25 July 2006
- USN-296-1
- firefox vulnerabilities
- 9 June 2006