Unrated severityNVD Advisory· Published Apr 6, 2006· Updated Jun 16, 2026
CVE-2006-1650
CVE-2006-1650
Description
Firefox 1.5.0.1 allows remote attackers to spoof the address bar and possibly conduct phishing attacks by re-opening the window to a malicious Shockwave Flash application, then changing the window location back to a trusted URL while the Flash application is still loading. NOTE: a followup was unable to replicate this issue.
Affected products
2- cpe:2.3:a:mozilla:firefox:1.5.0.1:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.