CVE-2006-2788

high
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

Double free vulnerability in the getRawDER function for nsIX509Cert in Firefox allows remote attackers to cause a denial of service (hang) and possibly execute arbitrary code via certain Javascript code.

References

http://rhn.redhat.com/errata/RHSA-2006-0609.html

http://secunia.com/advisories/21269

http://secunia.com/advisories/21270

http://secunia.com/advisories/21336

http://secunia.com/advisories/21532

http://secunia.com/advisories/21631

http://secunia.com/advisories/22247

http://secunia.com/advisories/22299

http://secunia.com/advisories/22342

http://secunia.com/advisories/22849

http://www.debian.org/security/2006/dsa-1192

http://www.debian.org/security/2006/dsa-1210

http://www.mandriva.com/security/advisories?name=MDKSA-2006:143

http://www.mandriva.com/security/advisories?name=MDKSA-2006:145

http://www.redhat.com/support/errata/RHSA-2006-0578.html

http://www.redhat.com/support/errata/RHSA-2006-0594.html

http://www.redhat.com/support/errata/RHSA-2006-0610.html

http://www.redhat.com/support/errata/RHSA-2006-0611.html

http://www.ubuntu.com/usn/usn-361-1

http://www.us.debian.org/security/2006/dsa-1191

https://bugzilla.mozilla.org/show_bug.cgi?id=321598

https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11065

https://usn.ubuntu.com/296-1/

Details

Source: MITRE

Published: 2006-06-02

Updated: 2018-10-03

Type: CWE-119

Risk Information

CVSS v2

Base Score: 7.5

Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Impact Score: 6.4

Exploitability Score: 10

Severity: HIGH

Tenable Plugins

View all (23 total)

IDNameProductFamilySeverity
67424Oracle Linux 4 : thunderbird (ELSA-2006-0735 / ELSA-2006-0677 / ELBA-2006-0624 / ELSA-2006-0611)NessusOracle Linux Local Security Checks
critical
67422Oracle Linux 4 : firefox (ELSA-2006-0733 / ELSA-2006-0675 / ELSA-2006-0610)NessusOracle Linux Local Security Checks
critical
27941Ubuntu 5.04 / 5.10 : mozilla vulnerabilities (USN-361-1)NessusUbuntu Local Security Checks
critical
27869Ubuntu 5.04 / 5.10 : firefox, mozilla-firefox vulnerabilities (USN-296-2)NessusUbuntu Local Security Checks
high
27868Ubuntu 6.06 LTS : firefox vulnerabilities (USN-296-1)NessusUbuntu Local Security Checks
high
23892Mandrake Linux Security Advisory : mozilla-firefox (MDKSA-2006:143-1)NessusMandriva Local Security Checks
critical
23659Debian DSA-1210-1 : mozilla-firefox - several vulnerabilitiesNessusDebian Local Security Checks
critical
22733Debian DSA-1192-1 : mozilla - several vulnerabilitiesNessusDebian Local Security Checks
critical
22732Debian DSA-1191-1 : mozilla-thunderbird - several vulnerabilitiesNessusDebian Local Security Checks
critical
3745Mozilla Thunderbird < 1.5.0.7 Multiple Vulnerabilities (deprecated)Nessus Network MonitorSMTP Clients
medium
3744SeaMonkey < 1.0.5 Multiple VulnerabilitiesNessus Network MonitorWeb Clients
medium
3743Mozilla Firefox 1.5.x < 1.5.0.7 Multiple VulnerabilitiesNessus Network MonitorWeb Clients
medium
22291RHEL 2.1 : seamonkey (RHSA-2006:0594)NessusRed Hat Local Security Checks
high
22163CentOS 4 : seamonkey (CESA-2006:0609)NessusCentOS Local Security Checks
high
22150RHEL 4 : seamonkey (RHSA-2006:0609)NessusRed Hat Local Security Checks
high
22138CentOS 4 : thunderbird (CESA-2006:0611)NessusCentOS Local Security Checks
high
22137CentOS 4 : Firefox (CESA-2006:0610)NessusCentOS Local Security Checks
high
22122RHEL 4 : thunderbird (RHSA-2006:0611)NessusRed Hat Local Security Checks
high
22121RHEL 4 : firefox (RHSA-2006:0610)NessusRed Hat Local Security Checks
high
22088RHEL 3 : seamonkey (RHSA-2006:0578)NessusRed Hat Local Security Checks
high
801305Mozilla Thunderbird < 1.5.0.7 Multiple VulnerabilitiesLog Correlation EngineSMTP Clients
high
800868SeaMonkey < 1.0.5 Multiple VulnerabilitiesLog Correlation EngineWeb Clients
high
800764Firefox < 1.5.0.7 Multiple VulnerabilitiesLog Correlation EngineWeb Clients
high