AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2006-2784

MEDIUM · CVSS 5.1 EPSS 1.79%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2006-06-02 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 5.1. It affects Firefox, Java. It may be remotely exploitable.

CVE
CVE-2006-2784
Severity
MEDIUM
CVSS
5.1
EPSS
1.79%
Firefox Java

Original NVD Description

The PLUGINSPAGE functionality in Mozilla Firefox before 1.5.0.4 allows remote user-assisted attackers to execute privileged code by tricking a user into installing missing plugins and selecting the "Manual Install" button, then using nested javascript: URLs. NOTE: the manual install button is used for downloading software from a remote web site, so this issue would not cross privilege boundaries if the user progresses to the point of installing malicious software from the attacker-controlled site.