Vulnerability Description
Mozilla Thunderbird before 1.5.0.7 and SeaMonkey before 1.0.5, with "Load Images" enabled, allows remote user-assisted attackers to bypass settings that disable JavaScript via a remote XBL file in a message that is loaded when the user views, forwards, or replies to the original message.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Seamonkey | <= 1.0.4 |
| Mozilla | Thunderbird | <= 1.5.0.6 |
References
- ftp://patches.sgi.com/support/free/security/advisories/20060901-01-P.asc
- http://secunia.com/advisories/21915
- http://secunia.com/advisories/21916
- http://secunia.com/advisories/21939
- http://secunia.com/advisories/21940
- http://secunia.com/advisories/22036
- http://secunia.com/advisories/22055
- http://secunia.com/advisories/22056
- http://secunia.com/advisories/22074
- http://secunia.com/advisories/22088
- http://secunia.com/advisories/22247
- http://secunia.com/advisories/22274
- http://secunia.com/advisories/22299
- http://secunia.com/advisories/22342
- http://secunia.com/advisories/22391
FAQ
What is CVE-2006-4570?
CVE-2006-4570 is a vulnerability with a CVSS score of 2.6 (LOW). Mozilla Thunderbird before 1.5.0.7 and SeaMonkey before 1.0.5, with "Load Images" enabled, allows remote user-assisted attackers to bypass settings that disable JavaScript via a remote XBL file in a m...
How severe is CVE-2006-4570?
CVE-2006-4570 has been rated LOW with a CVSS base score of 2.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2006-4570?
Check the references section above for vendor advisories and patch information. Affected products include: Mozilla Seamonkey, Mozilla Thunderbird.