CVE-2006-1736

N/A Unknown
Published: April 14, 2006 Modified: April 16, 2026
View on NVD

Description

Mozilla Firefox 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to trick users into downloading and saving an executable file via an image that is overlaid by a transparent image link that points to the executable, which causes the executable to be saved when the user clicks the "Save image as..." option. NOTE: this attack is made easier due to a GUI truncation issue that prevents the user from seeing the malicious extension when there is extra whitespace in the filename.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://secunia.com/advisories/19631
Source: secalert@redhat.com
http://secunia.com/advisories/19721
Source: secalert@redhat.com
http://secunia.com/advisories/19746
Source: secalert@redhat.com
http://secunia.com/advisories/19759
Source: secalert@redhat.com
http://secunia.com/advisories/19794
Source: secalert@redhat.com
http://secunia.com/advisories/19852
Source: secalert@redhat.com
http://secunia.com/advisories/19862
Source: secalert@redhat.com
http://secunia.com/advisories/19863
Source: secalert@redhat.com
http://secunia.com/advisories/19902
Source: secalert@redhat.com
http://secunia.com/advisories/19941
Source: secalert@redhat.com
http://secunia.com/advisories/21033
Source: secalert@redhat.com
http://secunia.com/advisories/21622
Source: secalert@redhat.com
http://www.securityfocus.com/bid/17516
Source: secalert@redhat.com
https://usn.ubuntu.com/271-1/
Source: secalert@redhat.com
https://usn.ubuntu.com/275-1/
Source: secalert@redhat.com
http://secunia.com/advisories/19631
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/19721
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/19746
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/19759
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/19794
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/19852
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/19862
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/19863
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/19902
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/19941
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/21033
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/21622
Source: af854a3a-2127-422b-91ae-364da2661108
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102550-1
Source: af854a3a-2127-422b-91ae-364da2661108
http://sunsolve.sun.com/search/document.do?assetkey=1-26-228526-1
Source: af854a3a-2127-422b-91ae-364da2661108
http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.debian.org/security/2006/dsa-1044
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.debian.org/security/2006/dsa-1046
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.debian.org/security/2006/dsa-1051
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.gentoo.org/security/en/glsa/glsa-200604-12.xml
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.gentoo.org/security/en/glsa/glsa-200604-18.xml
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.mandriva.com/security/advisories?name=MDKSA-2006:075
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.mandriva.com/security/advisories?name=MDKSA-2006:076
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.mozilla.org/security/announce/2006/mfsa2006-13.html
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/archive/1/438730/100/0/threaded
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/bid/17516
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2006/1356
Source: af854a3a-2127-422b-91ae-364da2661108
https://bugzilla.mozilla.org/show_bug.cgi?id=293527
Source: af854a3a-2127-422b-91ae-364da2661108
https://exchange.xforce.ibmcloud.com/vulnerabilities/25814
Source: af854a3a-2127-422b-91ae-364da2661108
https://usn.ubuntu.com/271-1/
Source: af854a3a-2127-422b-91ae-364da2661108
https://usn.ubuntu.com/275-1/
Source: af854a3a-2127-422b-91ae-364da2661108

66 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
1.6%
82th percentile
Exploitation Status
Not in CISA KEV

Affected Vendors

mozilla