Unspecified vulnerability in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to bypass same-origin protections and conduct cross-site scripting (XSS) attacks via unspecified vectors involving the window.controllers array. This vulnerability also affects Mozilla Suite before 1.7.13, and SeaMonkey before 1.0
This vulnerability is addressed in the following product releases:
Mozilla, Firefox, 1.5
Mozilla, Firefox, 1.0.8
Mozilla, Thunderbird, 1.5
Mozilla, Thunderbird, 1.0.8
Mozilla, SeaMonkey, 1.0
Mozilla, Suite, 1.7.13
Publication date: Fri, 14 Apr 2006 15:02:00 +0000