CVE-2006-1942

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
20/04/2006
Last modified:
18/10/2018

Description

Mozilla Firefox 1.5.0.2 and possibly other versions before 1.5.0.4, Netscape 8.1, 8.0.4, and 7.2, and K-Meleon 0.9.13 allows user-assisted remote attackers to open local files via a web page with an IMG element containing a SRC attribute with a non-image file:// URL, then tricking the user into selecting View Image for the broken image, as demonstrated using a .wma file to launch Windows Media Player, or by referencing an "alternate web page."

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:k-meleon_project:k-meleon:0.9.13:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:1.5.0.2:*:*:*:*:*:*:*
cpe:2.3:a:netscape:navigator:7.2:*:*:*:*:*:*:*
cpe:2.3:a:netscape:navigator:8.0.40:*:*:*:*:*:*:*
cpe:2.3:a:netscape:navigator:8.1:*:*:*:*:*:*:*