AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2006-1741

MEDIUM · CVSS 4.3 EPSS 3.89%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2006-04-14 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2006-1741
Severity
MEDIUM
CVSS
4.3
EPSS
3.89%
Firefox Java

Original NVD Description

Mozilla Firefox 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to inject arbitrary Javascript into other sites by (1) "using a modal alert to suspend an event handler while a new page is being loaded", (2) using eval(), and using certain variants involving (3) "new Script;" and (4) using window.__proto__ to extend eval, aka "cross-site JavaScript injection".