CVE-2006-3352 describes a cross-domain vulnerability initially reported in Mozilla Firefox, where an object tag could potentially allow remote attackers to access restricted information from other domains. However, this report was later retracted by the original authors and disputed by third parties, indicating it is not a genuine vulnerability. The CVSS score of 6.4 (AV:N/AC:L/Au:N/C:P/I:P/A:N) reflects a potential for partial confidentiality and integrity impact if it were a valid flaw, but this is now considered inaccurate. There is no evidence of active exploitation, no known exploit code (Metasploit, Nuclei, ExploitDB), and it has garnered no community discussion or media coverage, aligning with its status as a non-vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.8CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:0.8:*:*:*:*:*:*:* | ||
0.9CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:0.9:*:*:*:*:*:*:* | ||
0.9CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:0.9:rc:*:*:*:*:*:* | ||
0.9.1CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:0.9.1:*:*:*:*:*:*:* | ||
0.9.2CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:0.9.2:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.