Skip to content
appaloosa scout logo main rounded
N/A

CVE-2006-0299

The E4X implementation in Mozilla Firefox before 1.5.0.1, Thunderbird 1.5 if running Javascript in mail, and SeaMonkey before 1.0 exposes the internal "AnyName" object to external interfaces, which allows multiple cooperating domains to exchange information in violation of the same origin restrictions.

EPSS 1.4% percentile 80.9%

Affected tracked apps

Vulnerable CPE configurations

Vendor Product Platform Versions CPE 2.3 URI
mozilla thunderbird Windows cpe:2.3:a:mozilla:thunderbird:1.5:*:*:*:*:*:*:*
View on NVD ↗