Unrated severityNVD Advisory· Published Jun 2, 2006· Updated Jun 16, 2026
CVE-2006-2785
CVE-2006-2785
Description
Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 1.5.0.4 allows user-assisted remote attackers to inject arbitrary web script or HTML by tricking a user into (1) performing a "View Image" on a broken image in which the SRC attribute contains a Javascript URL, or (2) selecting "Show only this frame" on a frame whose SRC attribute contains a Javascript URL.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*range: <=1.5.0.3
- (no CPE)range: <1.5.0.4
Patches
Vulnerability mechanics
References
39- www.mozilla.org/security/announce/2006/mfsa2006-34.htmlnvdVendor Advisory
- rhn.redhat.com/errata/RHSA-2006-0609.htmlnvd
- secunia.com/advisories/20376nvd
- secunia.com/advisories/20561nvd
- secunia.com/advisories/21134nvd
- secunia.com/advisories/21176nvd
- secunia.com/advisories/21178nvd
- secunia.com/advisories/21183nvd
- secunia.com/advisories/21188nvd
- secunia.com/advisories/21269nvd
- secunia.com/advisories/21270nvd
- secunia.com/advisories/21324nvd
- secunia.com/advisories/21336nvd
- secunia.com/advisories/21532nvd
- secunia.com/advisories/21631nvd
- secunia.com/advisories/22066nvd
- securitytracker.com/idnvd
- www.debian.org/security/2006/dsa-1118nvd
- www.debian.org/security/2006/dsa-1120nvd
- www.debian.org/security/2006/dsa-1134nvd
- www.gentoo.org/security/en/glsa/glsa-200606-12.xmlnvd
- www.mandriva.com/security/advisoriesnvd
- www.mandriva.com/security/advisoriesnvd
- www.novell.com/linux/security/advisories/2006_35_mozilla.htmlnvd
- www.redhat.com/support/errata/RHSA-2006-0578.htmlnvd
- www.redhat.com/support/errata/RHSA-2006-0594.htmlnvd
- www.redhat.com/support/errata/RHSA-2006-0610.htmlnvd
- www.redhat.com/support/errata/RHSA-2006-0611.htmlnvd
- www.securityfocus.com/archive/1/435795/100/0/threadednvd
- www.securityfocus.com/archive/1/446658/100/200/threadednvd
- www.securityfocus.com/bid/18228nvd
- www.vupen.com/english/advisories/2006/2106nvd
- www.vupen.com/english/advisories/2006/3748nvd
- www.vupen.com/english/advisories/2008/0083nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/26845nvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10545nvd
- usn.ubuntu.com/296-1/nvd
- usn.ubuntu.com/296-2/nvd
- usn.ubuntu.com/323-1/nvd
News mentions
0No linked articles in our index yet.