Unrated severityNVD Advisory· Published Sep 6, 2006· Updated Jun 16, 2026
CVE-2006-4561
CVE-2006-4561
Description
Mozilla Firefox 1.5.0.6 allows remote attackers to execute arbitrary JavaScript in the context of the browser's session with an arbitrary intranet web server, by hosting script on an Internet web server that can be made inaccessible by the attacker and that has a domain name under the attacker's control, which can force the browser to drop DNS pinning and perform a new DNS query for the domain name after the script is already running.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2cpe:2.3:a:mozilla:firefox:1.5.0.6:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:mozilla:firefox:1.5.0.6:*:*:*:*:*:*:*
- (no CPE)range: = 1.5.0.6
Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.