CVE-2006-1731: XSS
Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 returns the Object class prototype instead of the global window object when (1) .valueOf.call or (2) .valueOf.apply are called without any arguments, which allows remote attackers to conduct cross-site scripting (XSS) attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-1731?
CVE-2006-1731 is classified as a moderate severity vulnerability.
How do I fix CVE-2006-1731?
To fix CVE-2006-1731, update Mozilla Firefox, Mozilla Suite, Thunderbird, or SeaMonkey to the latest version that addresses this vulnerability.
What versions are affected by CVE-2006-1731?
CVE-2006-1731 affects Mozilla Firefox versions before 1.5, Mozilla Suite versions before 1.7.13, Thunderbird versions before 1.5, and SeaMonkey before 1.0.
What type of attack can exploit CVE-2006-1731?
CVE-2006-1731 allows remote attackers to execute arbitrary JavaScript code in a browser security context via the Object class prototype.
Is there a workaround for CVE-2006-1731?
There are no effective workarounds for CVE-2006-1731; the only resolution is to update to a secure version.