CVE-2006-6503
Publication date 20 December 2006
Last updated 17 July 2025
Ubuntu priority
Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to bypass cross-site scripting (XSS) protection by changing the src attribute of an IMG element to a javascript: URI.
Status
Package | Ubuntu Release | Status |
---|---|---|
firefox | ||
firefox-3.0 | ||
iceape | ||
lightning-sunbird | ||
midbrowser | ||
mozilla-thunderbird | ||
xulrunner | ||