Lucene search

K
cveMitreCVE-2006-2778
HistoryJun 02, 2006 - 6:02 p.m.

CVE-2006-2778

2006-06-0218:02:00
mitre
web.nvd.nist.gov
63
cve-2006-2778
buffer overflow
mozilla firefox
thunderbird
remote code execution
certificate authority

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

AI Score

7.4

Confidence

Low

EPSS

0.419

Percentile

97.3%

The crypto.signText function in Mozilla Firefox and Thunderbird before 1.5.0.4 allows remote attackers to execute arbitrary code via certain optional Certificate Authority name arguments, which causes an invalid array index and triggers a buffer overflow.

Affected configurations

Nvd
Node
mozillafirefoxRange1.5.0.3
OR
mozillathunderbirdRange1.5.0.3
VendorProductVersionCPE
mozillafirefox*cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
mozillathunderbird*cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*

References

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

AI Score

7.4

Confidence

Low

EPSS

0.419

Percentile

97.3%