CVE-2006-2781
published 2006-06-02CVE-2006-2781: Double free vulnerability in nsVCard.cpp in Mozilla Thunderbird before 1.5.0.4 and SeaMonkey before 1.0.2 allows remote attackers to cause a denial of service…
PriorityP423medium6.4CVSS 2.0
AVNACLAuNCNIPAP
EPSS
3.31%
87.2th percentile
Double free vulnerability in nsVCard.cpp in Mozilla Thunderbird before 1.5.0.4 and SeaMonkey before 1.0.2 allows remote attackers to cause a denial of service (hang) and possibly execute arbitrary code via a VCard that contains invalid base64 characters.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | thunderbird | < thunderbird 1.5.0.4-1 (bookworm) | thunderbird 1.5.0.4-1 (bookworm) |
| mozilla | seamonkey | <= 1.0.1 | — |
| mozilla | thunderbird | <= 1.5.0.3 | — |
| mozilla | thunderbird | >= 0 < 1.5.0.4-1 | 1.5.0.4-1 |
| mozilla | thunderbird | >= 0 < 1.5.0.4-1 | 1.5.0.4-1 |
| mozilla | thunderbird | >= 0 < 1.5.0.4-1 | 1.5.0.4-1 |
| mozilla | thunderbird | >= 0 < 1.5.0.4-1 | 1.5.0.4-1 |
CVSS provenance
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:P
osv6.4MEDIUM
vendor_ubuntu7.5HIGH
vendor_debian6.4HIGH
vendor_redhat6.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-59hc-56j6-9j87: Double free vulnerability in nsVCard
ghsa_unreviewed·2022-05-01
CVE-2006-2781 [MEDIUM] CWE-119 GHSA-59hc-56j6-9j87: Double free vulnerability in nsVCard
Double free vulnerability in nsVCard.cpp in Mozilla Thunderbird before 1.5.0.4 and SeaMonkey before 1.0.2 allows remote attackers to cause a denial of service (hang) and possibly execute arbitrary code via a VCard that contains invalid base64 characters.
OSV
CVE-2006-2781: Double free vulnerability in nsVCard
osv·2006-06-02·CVSS 6.4
CVE-2006-2781 [MEDIUM] CVE-2006-2781: Double free vulnerability in nsVCard
Double free vulnerability in nsVCard.cpp in Mozilla Thunderbird before 1.5.0.4 and SeaMonkey before 1.0.2 allows remote attackers to cause a denial of service (hang) and possibly execute arbitrary code via a VCard that contains invalid base64 characters.
Ubuntu
mozilla vulnerabilities
vendor_ubuntu·2006-07-26·CVSS 4.3
CVE-2006-2775 [MEDIUM] mozilla vulnerabilities
Title: mozilla vulnerabilities
Summary: mozilla vulnerabilities
Jonas Sicking discovered that under some circumstances persisted XUL
attributes are associated with the wrong URL. A malicious web site
could exploit this to execute arbitrary code with the privileges of
the user. (MFSA 2006-35, CVE-2006-2775)
Paul Nickerson discovered that content-defined setters on an object
prototype were getting called by privileged UI code. It was
demonstrated that this could be exploited to run arbitrary web script
with full user privileges (MFSA 2006-37, CVE-2006-2776). A similar
attack was discovered by moz_bug_r_a4 that leveraged SelectionObject
notifications that were called in privileged context. (MFSA 2006-43,
CVE-2006-2777)
Mikolaj Habryn discovered a buffer overflow in the crypto.signText()
f
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2006-07-26·CVSS 7.5
CVE-2006-2775 [HIGH] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Thunderbird vulnerabilities
USN-297-1 fixed several vulnerabilities in Thunderbird for the Ubuntu
6.06 LTS release. This update provides the corresponding fixes for
Ubuntu 5.04 and Ubuntu 5.10.
For reference, these are the details of the original USN:
Jonas Sicking discovered that under some circumstances persisted XUL
attributes are associated with the wrong URL. A malicious web site
could exploit this to execute arbitrary code with the privileges of
the user. (MFSA 2006-35, CVE-2006-2775)
Paul Nickerson discovered that content-defined setters on an object
prototype were getting called by privileged UI code. It was
demonstrated that this could be exploited to run arbitrary web
script with full user privileges (MFSA 2006-37, CVE-2006-2776).
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2006-06-14·CVSS 7.5
CVE-2006-2775 [HIGH] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Thunderbird vulnerabilities
Jonas Sicking discovered that under some circumstances persisted XUL
attributes are associated with the wrong URL. A malicious web site
could exploit this to execute arbitrary code with the privileges of
the user. (MFSA 2006-35, CVE-2006-2775)
Paul Nickerson discovered that content-defined setters on an object
prototype were getting called by privileged UI code. It was
demonstrated that this could be exploited to run arbitrary web script
with full user privileges (MFSA 2006-37, CVE-2006-2776).
Mikolaj Habryn discovered a buffer overflow in the crypto.signText()
function. By sending an email with malicious JavaScript to an user,
and that user enabled JavaScript in Thunderbird (which is not the
default and not recomm
Red Hat
(seamonkey): DOS/arbitrary code execution vuln with vcards
vendor_redhat·2006-06-02·CVSS 6.4
CVE-2006-2781 [MEDIUM] (seamonkey): DOS/arbitrary code execution vuln with vcards
(seamonkey): DOS/arbitrary code execution vuln with vcards
Double free vulnerability in nsVCard.cpp in Mozilla Thunderbird before 1.5.0.4 and SeaMonkey before 1.0.2 allows remote attackers to cause a denial of service (hang) and possibly execute arbitrary code via a VCard that contains invalid base64 characters.
Debian
CVE-2006-2781: thunderbird - Double free vulnerability in nsVCard.cpp in Mozilla Thunderbird before 1.5.0.4 a...
vendor_debian·2006·CVSS 6.4
CVE-2006-2781 [MEDIUM] CVE-2006-2781: thunderbird - Double free vulnerability in nsVCard.cpp in Mozilla Thunderbird before 1.5.0.4 a...
Double free vulnerability in nsVCard.cpp in Mozilla Thunderbird before 1.5.0.4 and SeaMonkey before 1.0.2 allows remote attackers to cause a denial of service (hang) and possibly execute arbitrary code via a VCard that contains invalid base64 characters.
Scope: local
bookworm: resolved (fixed in 1.5.0.4-1)
bullseye: resolved (fixed in 1.5.0.4-1)
forky: resolved (fixed in 1.5.0.4-1)
sid: resolved (fixed in 1.5.0.4-1)
trixie: resolved (fixed in 1.5.0.4-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2006-2779 multiple Thunderbird issues (CVE-2006-2780, CVE-2006-2781, CVE-2006-2783,CVE-2006-2782,CVE-2006-2778,CVE-2006-2776,CVE-2006-2784,CVE-2006-2785,CVE-2006-2786,CVE-2006-2787,CVE-2006-2788)
bugzilla·2006-06-28·CVSS 7.5
CVE-2006-2779 [HIGH] CVE-2006-2779 multiple Thunderbird issues (CVE-2006-2780, CVE-2006-2781, CVE-2006-2783,CVE-2006-2782,CVE-2006-2778,CVE-2006-2776,CVE-2006-2784,CVE-2006-2785,CVE-2006-2786,CVE-2006-2787,CVE-2006-2788)
CVE-2006-2779 multiple Thunderbird issues (CVE-2006-2780, CVE-2006-2781, CVE-2006-2783,CVE-2006-2782,CVE-2006-2778,CVE-2006-2776,CVE-2006-2784,CVE-2006-2785,CVE-2006-2786,CVE-2006-2787,CVE-2006-2788)
+++ This bug was initially created as a clone of Bug #196973 +++
These issues will remain unfixed in Thunderbird until we upgrade to Thunderbird
1.5. They are not additional issues, simply problems which are fixed as part of
the upgrade.
CVE-2006-2777 MFSA 2006-43
CVE-2006-2776 MFSA 2006-37
CVE-2006-2784 MFSA 2006-36
CVE-2006-2785 MFSA 2006-34
CVE-2006-2787 MFSA 2006-31
Several flaws were found in the way Thunderbird processes certain javascript
actions. A malicious HTML mail could execute arbitrary javascript
instructions with the permissions of "chrome", allowing the mail to steal
sensiti
Bugzilla
CVE-2006-2779 Multiple Mozilla issues (CVE-2006-2781, CVE-2006-2788)
bugzilla·2006-06-14·CVSS 9.3
CVE-2006-2779 [CRITICAL] CVE-2006-2779 Multiple Mozilla issues (CVE-2006-2781, CVE-2006-2788)
CVE-2006-2779 Multiple Mozilla issues (CVE-2006-2781, CVE-2006-2788)
This was originally bug 194617, until Bugzilla barfed yesterday. Entering
it again...
Summary: CVE-2006-2779 Multiple Mozilla issues (CVE-2006-2781,
CVE-2006-2788)
Product: Fedora Core
Version: fc5
Platform: All
OS/Version: Linux
Status: NEW
Severity: urgent
Priority: normal
Component: firefox
AssignedTo: [email protected]
ReportedBy: [email protected]
CC: [email protected],[email protected]
This issue also affects Fedora Core 5. A lot of the problems fixed in 1.5.0.4
don't seem that severe, but a few of these are serious enough to at least turn
some heads. And it's been public for a quite a while now.
+++ This bug was initially created as a clone of Bug #193906 +++
Text stolen from MITRE:
CVE-2006-2781
Double-free
Bugzilla
CVE-2006-2779 Multiple Mozilla, Firefox issues (CVE-2006-2781, CVE-2006-2788)
bugzilla·2006-06-08·CVSS 9.3
CVE-2006-2779 [CRITICAL] CVE-2006-2779 Multiple Mozilla, Firefox issues (CVE-2006-2781, CVE-2006-2788)
CVE-2006-2779 Multiple Mozilla, Firefox issues (CVE-2006-2781, CVE-2006-2788)
+++ This bug was initially created as a clone of Bug #193906 +++
Text stolen from MITRE:
CVE-2006-2781
Double-free vulnerability in Mozilla Thunderbird before 1.5.0.4 and
SeaMonkey before 1.0.2 allows remote attackers to cause a denial of
service (hang) and possibly execute arbitrary code via a VCard that
contains invalid base64 characters.
CVE-2006-2779
Mozilla Firefox and Thunderbird before 1.5.0.4 allow remote attackers
to cause a denial of service (crash) and possibly execute arbitrary
code via (1) nested tags in a select tag, (2) a
DOMNodeRemoved mutation event, (3) "Content-implemented tree views,"
(4) BoxObjects, (5) the XBL implementation, (6) an iframe that
attempts to remove itself, which leads to m
Bugzilla
CVE-2006-2781 (seamonkey): DOS/arbitrary code execution vuln with vcards
bugzilla·2006-06-03·CVSS 6.4
CVE-2006-2781 [MEDIUM] CVE-2006-2781 (seamonkey): DOS/arbitrary code execution vuln with vcards
CVE-2006-2781 (seamonkey): DOS/arbitrary code execution vuln with vcards
vcard parsing related DOS/arbitrary code execution in seamonkey < 1.0.2:
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2006-2781
Discussion:
released 1.0.2 rpm, fixed
http://rhn.redhat.com/errata/RHSA-2006-0609.htmlhttp://secunia.com/advisories/20382http://secunia.com/advisories/20394http://secunia.com/advisories/20709http://secunia.com/advisories/21134http://secunia.com/advisories/21178http://secunia.com/advisories/21183http://secunia.com/advisories/21210http://secunia.com/advisories/21269http://secunia.com/advisories/21324http://secunia.com/advisories/21336http://secunia.com/advisories/21607http://secunia.com/advisories/21631http://secunia.com/advisories/22065http://securitytracker.com/id?1016214http://www.debian.org/security/2006/dsa-1118http://www.debian.org/security/2006/dsa-1134http://www.gentoo.org/security/en/glsa/glsa-200606-21.xmlhttp://www.mandriva.com/security/advisories?name=MDKSA-2006:146http://www.mozilla.org/security/announce/2006/mfsa2006-40.htmlhttp://www.novell.com/linux/security/advisories/2006_35_mozilla.htmlhttp://www.redhat.com/support/errata/RHSA-2006-0578.htmlhttp://www.redhat.com/support/errata/RHSA-2006-0594.htmlhttp://www.redhat.com/support/errata/RHSA-2006-0611.htmlhttp://www.securityfocus.com/archive/1/435795/100/0/threadedhttp://www.securityfocus.com/archive/1/446657/100/200/threadedhttp://www.securityfocus.com/bid/18228http://www.vupen.com/english/advisories/2006/2106http://www.vupen.com/english/advisories/2006/3749https://exchange.xforce.ibmcloud.com/vulnerabilities/26850https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10247https://usn.ubuntu.com/297-1/https://usn.ubuntu.com/297-3/https://usn.ubuntu.com/323-1/http://rhn.redhat.com/errata/RHSA-2006-0609.htmlhttp://secunia.com/advisories/20382http://secunia.com/advisories/20394http://secunia.com/advisories/20709http://secunia.com/advisories/21134http://secunia.com/advisories/21178http://secunia.com/advisories/21183http://secunia.com/advisories/21210http://secunia.com/advisories/21269http://secunia.com/advisories/21324http://secunia.com/advisories/21336http://secunia.com/advisories/21607http://secunia.com/advisories/21631http://secunia.com/advisories/22065http://securitytracker.com/id?1016214http://www.debian.org/security/2006/dsa-1118http://www.debian.org/security/2006/dsa-1134http://www.gentoo.org/security/en/glsa/glsa-200606-21.xmlhttp://www.mandriva.com/security/advisories?name=MDKSA-2006:146http://www.mozilla.org/security/announce/2006/mfsa2006-40.htmlhttp://www.novell.com/linux/security/advisories/2006_35_mozilla.htmlhttp://www.redhat.com/support/errata/RHSA-2006-0578.htmlhttp://www.redhat.com/support/errata/RHSA-2006-0594.htmlhttp://www.redhat.com/support/errata/RHSA-2006-0611.htmlhttp://www.securityfocus.com/archive/1/435795/100/0/threadedhttp://www.securityfocus.com/archive/1/446657/100/200/threadedhttp://www.securityfocus.com/bid/18228http://www.vupen.com/english/advisories/2006/2106http://www.vupen.com/english/advisories/2006/3749https://exchange.xforce.ibmcloud.com/vulnerabilities/26850https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10247https://usn.ubuntu.com/297-1/https://usn.ubuntu.com/297-3/https://usn.ubuntu.com/323-1/
2006-06-02
Published