AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2006-1993

MEDIUM · CVSS 5.1 EPSS 54.00%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2006-04-25 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2006-1993
Severity
MEDIUM
CVSS
5.1
EPSS
54.00%
Firefox Java

Original NVD Description

Mozilla Firefox 1.5.0.2, when designMode is enabled, allows remote attackers to cause a denial of service and possibly execute arbitrary code via certain Javascript that is not properly handled by the contentWindow.focus method in an iframe, which causes a reference to a deleted controller context object. NOTE: this was originally claimed to be a buffer overflow in (1) js320.dll and (2) xpcom_core.dll, but the vendor disputes this claim.