[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250108

 
 

909

 
 

196064

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2006-6585Date: (C)2006-12-15   (M)2023-12-22


The Extensions manager in Mozilla Firefox 2.0 does not properly populate the list of local extensions, which allows attackers to construct an extension that hides itself by finding its name in the list and then calling RemoveElement, as demonstrated by the FFsniFF extension. NOTE: it was later reported that 3.0 is also affected.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 6.4
Exploit Score: 10.0
Impact Score: 4.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: NONE
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
http://www.securityfocus.com/archive/1/archive/1/454058/100/0/threaded
http://www.securityfocus.com/archive/1/archive/1/493585/100/0/threaded
SREASON-2046
http://azurit.elbiahosting.sk/ffsniff/ffsniff-0.2.tar.gz

CPE    2
cpe:/a:mozilla:firefox:2.0
cpe:/a:mozilla:firefox:3.0

© SecPod Technologies