CVE-2006-6971: Input Validation

Published Feb 7, 2007
·
Updated

Mozilla Firefox 2.0, possibly only when running on Windows, allows remote attackers to bypass the Phishing Protection mechanism by representing an IP address in (1) dotted-hex, (2) dotted-octal, (3) single decimal integer, (4) single hex integer, or (5) single octal integer format, which is not captured by the blacklist filter.

Affected Software

1 affected component
Mozilla Firefox=2.0.0.1

Event History

Feb 7, 2007
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-2006-6971?

CVE-2006-6971 is classified as a moderate severity vulnerability.

2

How does CVE-2006-6971 allow phishing attacks?

CVE-2006-6971 allows attackers to bypass the Phishing Protection mechanism by representing IP addresses in various misleading formats.

3

Which version of Mozilla Firefox is affected by CVE-2006-6971?

CVE-2006-6971 specifically affects Mozilla Firefox version 2.0.0.1 on Windows.

4

Is there a patch available for CVE-2006-6971?

A patch is available by updating to a later version of Mozilla Firefox beyond 2.0.0.1.

5

What types of IP address formats are exploited in CVE-2006-6971?

CVE-2006-6971 exploits IP addresses represented in dotted-hex, dotted-octal, single decimal, single hex, or single octal integer formats.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203