CVE-2006-1730
high · 9.3Integer overflow in Mozilla Firefox and Thunderbird 1.x before 1.5.0.2 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0.1 allows remote attackers to execute arbitrary code via a large number in the CSS letter-spacing property that leads to a heap-based buffer overflow.
9.3
CVSS
10.3%
EPSS (exploit prob.)
95th
EPSS percentile
2006-04-14
Published
AV:N/AC:M/Au:N/C:C/I:C/A:C
Weaknesses
CWE-189
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| mozilla | firefox | 1.0 |
| mozilla | firefox | 1.0.1 |
| mozilla | firefox | 1.0.2 |
| mozilla | firefox | 1.0.3 |
| mozilla | firefox | 1.0.4 |
| mozilla | firefox | 1.0.5 |
| mozilla | firefox | 1.0.6 |
| mozilla | firefox | 1.0.7 |
| mozilla | firefox | 1.5 |
| mozilla | firefox | 1.5 |
| mozilla | firefox | 1.5 |
| mozilla | firefox | 1.5.0.1 |
| mozilla | mozilla_suite | 1.7.6 |
| mozilla | mozilla_suite | 1.7.7 |
| mozilla | mozilla_suite | 1.7.8 |
| mozilla | mozilla_suite | 1.7.10 |
| mozilla | mozilla_suite | 1.7.11 |
| mozilla | mozilla_suite | 1.7.12 |
| mozilla | seamonkey | 1.0 |
| mozilla | seamonkey | 1.0 |
| mozilla | thunderbird | 1.0 |
| mozilla | thunderbird | 1.0.1 |
| mozilla | thunderbird | 1.0.2 |
| mozilla | thunderbird | 1.0.3 |
| mozilla | thunderbird | 1.0.4 |
| mozilla | thunderbird | 1.0.5 |
| mozilla | thunderbird | 1.0.5 |
| mozilla | thunderbird | 1.0.6 |
| mozilla | thunderbird | 1.0.7 |
| mozilla | thunderbird | 1.5 |
| mozilla | thunderbird | 1.5 |
| mozilla | thunderbird | 1.5.0.1 |
Check a specific version with /api/v1/cve/match.
References
- ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.26/SCOSA-2006.26.txt
- ftp://patches.sgi.com/support/free/security/advisories/20060404-01-U.asc
- http://lists.suse.com/archive/suse-security-announce/2006-Apr/0003.html
- http://secunia.com/advisories/19631
- http://secunia.com/advisories/19649
- http://secunia.com/advisories/19696
- http://secunia.com/advisories/19714
- http://secunia.com/advisories/19721
- http://secunia.com/advisories/19729
- http://secunia.com/advisories/19746
- http://secunia.com/advisories/19759
- http://secunia.com/advisories/19780
- http://secunia.com/advisories/19794
- http://secunia.com/advisories/19811
- http://secunia.com/advisories/19821
- http://secunia.com/advisories/19823
- http://secunia.com/advisories/19852
- http://secunia.com/advisories/19862
- http://secunia.com/advisories/19863
- http://secunia.com/advisories/19902
- http://secunia.com/advisories/19941
- http://secunia.com/advisories/19950
- http://secunia.com/advisories/20051
- http://secunia.com/advisories/21033
- http://secunia.com/advisories/21622
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2006-1730