Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2006-1942

Опубликовано: 20 апр. 2006
Источник: nvd
CVSS2: 5.1
EPSS Низкий

Описание

Mozilla Firefox 1.5.0.2 and possibly other versions before 1.5.0.4, Netscape 8.1, 8.0.4, and 7.2, and K-Meleon 0.9.13 allows user-assisted remote attackers to open local files via a web page with an IMG element containing a SRC attribute with a non-image file:// URL, then tricking the user into selecting View Image for the broken image, as demonstrated using a .wma file to launch Windows Media Player, or by referencing an "alternate web page."

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:k-meleon_project:k-meleon:0.9.13:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:1.5.0.2:*:*:*:*:*:*:*
cpe:2.3:a:netscape:navigator:7.2:*:*:*:*:*:*:*
cpe:2.3:a:netscape:navigator:8.0.40:*:*:*:*:*:*:*
cpe:2.3:a:netscape:navigator:8.1:*:*:*:*:*:*:*

EPSS

Процентиль: 86%
0.0294
Низкий

5.1 Medium

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

ubuntu
больше 19 лет назад

Mozilla Firefox 1.5.0.2 and possibly other versions before 1.5.0.4, Netscape 8.1, 8.0.4, and 7.2, and K-Meleon 0.9.13 allows user-assisted remote attackers to open local files via a web page with an IMG element containing a SRC attribute with a non-image file:// URL, then tricking the user into selecting View Image for the broken image, as demonstrated using a .wma file to launch Windows Media Player, or by referencing an "alternate web page."

debian
больше 19 лет назад

Mozilla Firefox 1.5.0.2 and possibly other versions before 1.5.0.4, Ne ...

github
больше 3 лет назад

Mozilla Firefox 1.5.0.2 and possibly other versions before 1.5.0.4, Netscape 8.1, 8.0.4, and 7.2, and K-Meleon 0.9.13 allows user-assisted remote attackers to open local files via a web page with an IMG element containing a SRC attribute with a non-image file:// URL, then tricking the user into selecting View Image for the broken image, as demonstrated using a .wma file to launch Windows Media Player, or by referencing an "alternate web page."

EPSS

Процентиль: 86%
0.0294
Низкий

5.1 Medium

CVSS2

Дефекты

NVD-CWE-Other