PublicDate: 2006-02-02 23:06:00 UTC Candidate: CVE-2006-0299 References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0299 Description: The E4X implementation in Mozilla Firefox before 1.5.0.1, Thunderbird 1.5 if running Javascript in mail, and SeaMonkey before 1.0 exposes the internal "AnyName" object to external interfaces, which allows multiple cooperating domains to exchange information in violation of the same origin restrictions. Ubuntu-Description: Notes: Priority: untriaged Discovered-by: Assigned-to: CVSS: Bugs: dapper_midbrowser: DNE edgy_midbrowser: DNE feisty_midbrowser: DNE devel_midbrowser: released (0.1.6b-0ubuntu2) dapper_mozilla-thunderbird: released (1.5.0.13-0ubuntu0.6.06) edgy_mozilla-thunderbird: released (1.5.0.13-0ubuntu0.6.10) feisty_mozilla-thunderbird: released (1.5.0.13-0ubuntu0.7.04) devel_mozilla-thunderbird: DNE dapper_firefox-granparadiso: DNE edgy_firefox-granparadiso: DNE feisty_firefox-granparadiso: DNE devel_firefox-granparadiso: released (3.0~alpha7-0ubuntu6) dapper_firefox: released (1.5.dfsg+1.5.0.13~prepatch070731-0ubuntu1) edgy_firefox: released (2.0.0.6+0dfsg-0ubuntu0.6.10) feisty_firefox: released (2.0.0.6+1-0ubuntu1) dapper_lightning-sunbird: DNE edgy_lightning-sunbird: DNE feisty_lightning-sunbird: DNE devel_lightning-sunbird: released (0.5-0ubuntu4) upstream_firefox: needs-triage upstream_firefox-granparadiso: needs-triage upstream_lightning-sunbird: needs-triage upstream_midbrowser: needs-triage upstream_mozilla-thunderbird: needs-triage