AUGUST 4, 2026
Live Feed
Return to register
Case File

CVE-2006-6919

MEDIUM · CVSS 6.8 EPSS 2.07%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2007-01-11 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

CVE
CVE-2006-6919
Severity
MEDIUM
CVSS
6.8
EPSS
2.07%
Firefox Java

Original Filing — NVD Description

Firefox Sage extension 1.3.8 and earlier allows remote attackers to execute arbitrary Javascript in the local context via an RSS feed with an img tag containing the script followed by an extra trailing ">", which Sage modifies to close the img element before the malicious script.