← All CVEs

CVE-2006-1730

high · 9.3

Integer overflow in Mozilla Firefox and Thunderbird 1.x before 1.5.0.2 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0.1 allows remote attackers to execute arbitrary code via a large number in the CSS letter-spacing property that leads to a heap-based buffer overflow.

9.3
CVSS
10.3%
EPSS (exploit prob.)
95th
EPSS percentile
2006-04-14
Published

AV:N/AC:M/Au:N/C:C/I:C/A:C

Weaknesses

CWE-189

Affected products

VendorProductAffected versions
mozillafirefox1.0
mozillafirefox1.0.1
mozillafirefox1.0.2
mozillafirefox1.0.3
mozillafirefox1.0.4
mozillafirefox1.0.5
mozillafirefox1.0.6
mozillafirefox1.0.7
mozillafirefox1.5
mozillafirefox1.5
mozillafirefox1.5
mozillafirefox1.5.0.1
mozillamozilla_suite1.7.6
mozillamozilla_suite1.7.7
mozillamozilla_suite1.7.8
mozillamozilla_suite1.7.10
mozillamozilla_suite1.7.11
mozillamozilla_suite1.7.12
mozillaseamonkey1.0
mozillaseamonkey1.0
mozillathunderbird1.0
mozillathunderbird1.0.1
mozillathunderbird1.0.2
mozillathunderbird1.0.3
mozillathunderbird1.0.4
mozillathunderbird1.0.5
mozillathunderbird1.0.5
mozillathunderbird1.0.6
mozillathunderbird1.0.7
mozillathunderbird1.5
mozillathunderbird1.5
mozillathunderbird1.5.0.1

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2006-1730