Lucene search

K
cveRedhatCVE-2006-4567
HistorySep 15, 2006 - 6:07 p.m.

CVE-2006-4567

2006-09-1518:07:00
redhat
web.nvd.nist.gov
62
mozilla firefox
thunderbird
cve-2006-4567
security vulnerability
certificate validation
remote attack
dns spoofing

CVSS2

2.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:N/C:N/I:P/A:N

AI Score

6.4

Confidence

Low

EPSS

0.019

Percentile

88.6%

Mozilla Firefox before 1.5.0.7 and Thunderbird before 1.5.0.7 makes it easy for users to accept self-signed certificates for the auto-update mechanism, which might allow remote user-assisted attackers to use DNS spoofing to trick users into visiting a malicious site and accepting a malicious certificate for the Mozilla update site, which can then be used to install arbitrary code on the next update.

Affected configurations

Nvd
Node
mozillafirefoxRange1.5.0.6
OR
mozillathunderbirdRange1.5.0.6
VendorProductVersionCPE
mozillathunderbirdcpe:/a:mozilla:thunderbird::::
mozillafirefoxcpe:/a:mozilla:firefox::::

References

CVSS2

2.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:N/C:N/I:P/A:N

AI Score

6.4

Confidence

Low

EPSS

0.019

Percentile

88.6%