Skip to content
Appaloosa Scout

Vulnerability · NVD

CVE-2006-2783

N/A

Mozilla Firefox and Thunderbird before 1.5.0.4 strip the Unicode Byte-order-Mark (BOM) from a UTF-8 page before the page is passed to the parser, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a BOM sequence in the middle of a dangerous tag such as SCRIPT.

EPSS 1.67% above median percentile 74.6%

Tracked apps referencing this CVE

For each app: the affected range, the fixing version, and where the tracked app stands today.

Vulnerable CPE configurations (1)
Vendor Product Versions
mozilla thunderbird
All platforms (wildcard)
≤1.5.0.3
View on NVD ↗ Advisory · rhn.redhat.com Advisory · secunia.com Advisory · www.redhat.com