CVE-2006-3804
published 2006-07-27CVE-2006-3804: Heap-based buffer overflow in Mozilla Thunderbird before 1.5.0.5 and SeaMonkey before 1.0.3 allows remote attackers to cause a denial of service (crash) via a…
PriorityP423medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
3.25%
86.9th percentile
Heap-based buffer overflow in Mozilla Thunderbird before 1.5.0.5 and SeaMonkey before 1.0.3 allows remote attackers to cause a denial of service (crash) via a VCard attachment with a malformed base64 field, which copies more data than expected due to an integer underflow.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | thunderbird | < thunderbird 1.5.0.5-1 (bookworm) | thunderbird 1.5.0.5-1 (bookworm) |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | thunderbird | — | — |
| mozilla | thunderbird | — | — |
| mozilla | thunderbird | — | — |
| mozilla | thunderbird | >= 0 < 1.5.0.5-1 | 1.5.0.5-1 |
| mozilla | thunderbird | >= 0 < 1.5.0.5-1 | 1.5.0.5-1 |
| mozilla | thunderbird | >= 0 < 1.5.0.5-1 | 1.5.0.5-1 |
| mozilla | thunderbird | >= 0 < 1.5.0.5-1 | 1.5.0.5-1 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_ubuntu7.5HIGH
vendor_debian5.0HIGH
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2006-09-22·CVSS 7.5
CVE-2006-3113 [HIGH] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Thunderbird vulnerabilities
This update upgrades Thunderbird from 1.0.8 to 1.5.0.7. This step was
necessary since the 1.0.x series is not supported by upstream any
more.
Various flaws have been reported that allow an attacker to execute
arbitrary code with user privileges by tricking the user into opening
a malicious email containing JavaScript. Please note that JavaScript
is disabled by default for emails, and it is not recommended to enable
it. (CVE-2006-3113, CVE-2006-3802, CVE-2006-3803, CVE-2006-3805,
CVE-2006-3806, CVE-2006-3807, CVE-2006-3809, CVE-2006-3810,
CVE-2006-3811, CVE-2006-3812, CVE-2006-4253, CVE-2006-4565,
CVE-2006-4566, CVE-2006-4571)
A buffer overflow has been discovered in the handling of .vcard files.
By tricking a user
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2006-07-29·CVSS 7.2
CVE-2006-3113 [HIGH] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Thunderbird vulnerabilities
Various flaws have been reported that allow an attacker to execute
arbitrary code with user privileges by tricking the user into opening
a malicious email containing JavaScript. Please note that JavaScript
is disabled by default for emails, and it is not recommended to enable
it. (CVE-2006-3113, CVE-2006-3802, CVE-2006-3803, CVE-2006-3805,
CVE-2006-3806, CVE-2006-3807, CVE-2006-3809, CVE-2006-3810,
CVE-2006-3811, CVE-2006-3812)
A buffer overflow has been discovered in the handling of .vcard files.
By tricking a user into importing a malicious vcard into his contacts,
this could be exploited to execute arbitrary code with the user's
privileges. (CVE-2006-3084)
The "enigmail" plugin has been updated to work with the
Red Hat
security flaw
vendor_redhat·2006-07-26·CVSS 5.0
CVE-2006-3804 [MEDIUM] security flaw
security flaw
Heap-based buffer overflow in Mozilla Thunderbird before 1.5.0.5 and SeaMonkey before 1.0.3 allows remote attackers to cause a denial of service (crash) via a VCard attachment with a malformed base64 field, which copies more data than expected due to an integer underflow.
Debian
CVE-2006-3804: thunderbird - Heap-based buffer overflow in Mozilla Thunderbird before 1.5.0.5 and SeaMonkey b...
vendor_debian·2006·CVSS 5.0
CVE-2006-3804 [MEDIUM] CVE-2006-3804: thunderbird - Heap-based buffer overflow in Mozilla Thunderbird before 1.5.0.5 and SeaMonkey b...
Heap-based buffer overflow in Mozilla Thunderbird before 1.5.0.5 and SeaMonkey before 1.0.3 allows remote attackers to cause a denial of service (crash) via a VCard attachment with a malformed base64 field, which copies more data than expected due to an integer underflow.
Scope: local
bookworm: resolved (fixed in 1.5.0.5-1)
bullseye: resolved (fixed in 1.5.0.5-1)
forky: resolved (fixed in 1.5.0.5-1)
sid: resolved (fixed in 1.5.0.5-1)
trixie: resolved (fixed in 1.5.0.5-1)
GHSA
GHSA-gf24-q725-m5hh: Heap-based buffer overflow in Mozilla Thunderbird before 1
ghsa_unreviewed·2022-05-03
CVE-2006-3804 [MEDIUM] GHSA-gf24-q725-m5hh: Heap-based buffer overflow in Mozilla Thunderbird before 1
Heap-based buffer overflow in Mozilla Thunderbird before 1.5.0.5 and SeaMonkey before 1.0.3 allows remote attackers to cause a denial of service (crash) via a VCard attachment with a malformed base64 field, which copies more data than expected due to an integer underflow.
OSV
CVE-2006-3804: Heap-based buffer overflow in Mozilla Thunderbird before 1
osv·2006-07-27·CVSS 5.0
CVE-2006-3804 [MEDIUM] CVE-2006-3804: Heap-based buffer overflow in Mozilla Thunderbird before 1
Heap-based buffer overflow in Mozilla Thunderbird before 1.5.0.5 and SeaMonkey before 1.0.3 allows remote attackers to cause a denial of service (crash) via a VCard attachment with a malformed base64 field, which copies more data than expected due to an integer underflow.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2006-3804 security flaw
bugzilla·2018-08-16·CVSS 5.0
CVE-2006-3804 [MEDIUM] CVE-2006-3804 security flaw
CVE-2006-3804 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
Heap-based buffer overflow in Mozilla Thunderbird before 1.5.0.5 and SeaMonkey before 1.0.3 allows remote attackers to cause a denial of service (crash) via a VCard attachment with a malformed base64 field, which copies more data than expected due to an integer underflow.
Bugzilla
CVE-2006-3801, CVE-2006-3805, CVE-2006-3806, CVE-2006-3807, CVE-2006-3808, CVE-2006-3809, CVE-2006-3811, CVE-2006-3812: major (public) security flaws fixed in firefox 1.5.0.5
bugzilla·2006-07-28·CVSS 7.5
CVE-2006-3801 [HIGH] CVE-2006-3801, CVE-2006-3805, CVE-2006-3806, CVE-2006-3807, CVE-2006-3808, CVE-2006-3809, CVE-2006-3811, CVE-2006-3812: major (public) security flaws fixed in firefox 1.5.0.5
CVE-2006-3801, CVE-2006-3805, CVE-2006-3806, CVE-2006-3807, CVE-2006-3808, CVE-2006-3809, CVE-2006-3811, CVE-2006-3812: major (public) security flaws fixed in firefox 1.5.0.5
+++ This bug was initially created as a clone of Bug #200357 +++
Description of problem: Firefox 1.5.0.4 and earlier has serious security
flaws, patched in 1.5.0.5
http://www.mozilla.org/projects/security/known-vulnerabilities.html#firefox1.5.0.5
From the link above, I think the following also affect 1.0.8 in FC4:
CVE-2006-3805 : remote code execution via javascript.
CVE-2006-3806 : ditto.
CVE-2006-3807 : looks like a very serious privledge escalation bug for
javascript
CVE-2006-3808 : malicious proxy can execute code with privs it shouldn't have;
note that a malicious proxy can do all sorts of bad things
anyway.
Bugzilla
Seamonkey multiple vulnerabilities: CVE-2006-{3113,3677,3801-3812}
bugzilla·2006-07-27·CVSS 7.5
CVE-2006-3677 [HIGH] Seamonkey multiple vulnerabilities: CVE-2006-{3113,3677,3801-3812}
Seamonkey multiple vulnerabilities: CVE-2006-{3113,3677,3801-3812}
Arbitrary code execution:
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2006-3677
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2006-3803
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2006-3806
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2006-3807
Denial of service:
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2006-3804
All these are reported against seamonkey < 1.0.3. FE[45] and devel affected.
Discussion:
There's more: CVE-2006-3113, CVE-2006-3801, CVE-2006-3802, CVE-2006-3805,
CVE-2006-3808, CVE-2006-3809, CVE-2006-3810, CVE-2006-3811
---
...and CVE-2006-3812
---
See also related Firefox bug #200357
---
Fixed in 1.0.3+ according to upstream.
Bugzilla
major (public) security flaws fixed in firefox 1.5.0.5: CVE-2006-3113, CVE-2006-3677, CVE-2006-3801, CVE-2006-3802, CVE-2006-3803,CVE-2006-3805, CVE-2006-3806, CVE-2006-3807, CVE-2006-3808, CVE-2006-3
bugzilla·2006-07-27·CVSS 7.5
CVE-2006-3113 [HIGH] major (public) security flaws fixed in firefox 1.5.0.5: CVE-2006-3113, CVE-2006-3677, CVE-2006-3801, CVE-2006-3802, CVE-2006-3803,CVE-2006-3805, CVE-2006-3806, CVE-2006-3807, CVE-2006-3808, CVE-2006-3
major (public) security flaws fixed in firefox 1.5.0.5: CVE-2006-3113, CVE-2006-3677, CVE-2006-3801, CVE-2006-3802, CVE-2006-3803,CVE-2006-3805, CVE-2006-3806, CVE-2006-3807, CVE-2006-3808, CVE-2006-3809, CVE-2006-3810, CVE-2006-3811, CVE-2006-3812
Description of problem: Firefox 1.5.0.4 and earlier has serious security
flaws, patched in 1.5.0.5
Version-Release number of selected component (if applicable): 1.5.0.4 and earlier
How reproducible: always
Steps to Reproduce:
1. Just use Firefox!
2.
3.
Actual results: Security flaws.
Expected results: No security flaws.
Additional info: See: http://www.mozilla.org/security/announce/
for the dozen or so security announcements from Mozilla, namely,
MFSA 2006-44 through 56.
I left this open for everyone to see since the disclosure is p
Bugzilla
CVE-2006-3801 Multiple Seamonkey issues (CVE-2006-3677, CVE-2006-3113, CVE-2006-3802, CVE-2006-3803, CVE-2006-3804, CVE-2006-3805, CVE-2006-3806, CVE-2006-3807, CVE-2006-3808, CVE-2006-3809, CVE-2006-
bugzilla·2006-07-26·CVSS 7.5
CVE-2006-3801 [HIGH] CVE-2006-3801 Multiple Seamonkey issues (CVE-2006-3677, CVE-2006-3113, CVE-2006-3802, CVE-2006-3803, CVE-2006-3804, CVE-2006-3805, CVE-2006-3806, CVE-2006-3807, CVE-2006-3808, CVE-2006-3809, CVE-2006-
CVE-2006-3801 Multiple Seamonkey issues (CVE-2006-3677, CVE-2006-3113, CVE-2006-3802, CVE-2006-3803, CVE-2006-3804, CVE-2006-3805, CVE-2006-3806, CVE-2006-3807, CVE-2006-3808, CVE-2006-3809, CVE-2006-3810, CVE-2006-3811, CVE-2006-3812)
+++ This bug was initially created as a clone of Bug #200167 +++
Several Issues were discovered in Seamonkey, they are expected to be fixed in
the next upstream Seamonkey release
CVE-2006-3807 MFSA 2006-51
CVE-2006-3809 MFSA 2006-53
CVE-2006-3812 MFSA 2006-56
Several flaws were found in the way Seamonkey processes certain javascript
actions. A malicious web page could execute arbitrary javascript
instructions with the permissions of "chrome", allowing the page to steal
sensitive information or install browser malware.
CVE-2006-3801 MFSA 2006-44
CVE-200
Bugzilla
CVE-2006-3801 Multiple Seamonkey issues (CVE-2006-3677, CVE-2006-3113, CVE-2006-3802, CVE-2006-3803, CVE-2006-3804, CVE-2006-3805, CVE-2006-3806, CVE-2006-3807, CVE-2006-3808, CVE-2006-3809, CVE-2006-
bugzilla·2006-07-25·CVSS 7.5
CVE-2006-3801 [HIGH] CVE-2006-3801 Multiple Seamonkey issues (CVE-2006-3677, CVE-2006-3113, CVE-2006-3802, CVE-2006-3803, CVE-2006-3804, CVE-2006-3805, CVE-2006-3806, CVE-2006-3807, CVE-2006-3808, CVE-2006-3809, CVE-2006-
CVE-2006-3801 Multiple Seamonkey issues (CVE-2006-3677, CVE-2006-3113, CVE-2006-3802, CVE-2006-3803, CVE-2006-3804, CVE-2006-3805, CVE-2006-3806, CVE-2006-3807, CVE-2006-3808, CVE-2006-3809, CVE-2006-3810, CVE-2006-3811, CVE-2006-3812)
Several Issues were discovered in Seamonkey, they are expected to be fixed in
the next upstream Seamonkey release
CVE-2006-3807 MFSA 2006-51
CVE-2006-3809 MFSA 2006-53
CVE-2006-3812 MFSA 2006-56
Several flaws were found in the way Seamonkey processes certain javascript
actions. A malicious web page could execute arbitrary javascript
instructions with the permissions of "chrome", allowing the page to steal
sensitive information or install browser malware.
CVE-2006-3801 MFSA 2006-44
CVE-2006-3677 MFSA 2006-45
CVE-2006-3113 MFSA 2006-46
CVE-2006-3803 MFSA
Bugzilla
CVE-2006-3801 Multiple Seamonkey issues (CVE-2006-3677, CVE-2006-3113, CVE-2006-3802, CVE-2006-3803, CVE-2006-3804, CVE-2006-3805, CVE-2006-3806, CVE-2006-3807, CVE-2006-3808, CVE-2006-3809, CVE-2006-
bugzilla·2006-07-25·CVSS 7.5
CVE-2006-3801 [HIGH] CVE-2006-3801 Multiple Seamonkey issues (CVE-2006-3677, CVE-2006-3113, CVE-2006-3802, CVE-2006-3803, CVE-2006-3804, CVE-2006-3805, CVE-2006-3806, CVE-2006-3807, CVE-2006-3808, CVE-2006-3809, CVE-2006-
CVE-2006-3801 Multiple Seamonkey issues (CVE-2006-3677, CVE-2006-3113, CVE-2006-3802, CVE-2006-3803, CVE-2006-3804, CVE-2006-3805, CVE-2006-3806, CVE-2006-3807, CVE-2006-3808, CVE-2006-3809, CVE-2006-3810, CVE-2006-3811, CVE-2006-3812)
+++ This bug was initially created as a clone of Bug #200161 +++
Several Issues were discovered in Seamonkey, they are expected to be fixed in
the next upstream Seamonkey release
CVE-2006-3807 MFSA 2006-51
CVE-2006-3809 MFSA 2006-53
CVE-2006-3812 MFSA 2006-56
Several flaws were found in the way Seamonkey processes certain javascript
actions. A malicious web page could execute arbitrary javascript
instructions with the permissions of "chrome", allowing the page to steal
sensitive information or install browser malware.
CVE-2006-3801 MFSA 2006-44
CVE-200
Bugzilla
CVE-2006-3801 Multiple Thunderbird issues (CVE-2006-3677, CVE-2006-3113, CVE-2006-3802, CVE-2006-3803, CVE-2006-3804, CVE-2006-3805, CVE-2006-3806, CVE-2006-3807, CVE-2006-3808, CVE-2006-3809, CVE-200
bugzilla·2006-07-25·CVSS 7.5
CVE-2006-3801 [HIGH] CVE-2006-3801 Multiple Thunderbird issues (CVE-2006-3677, CVE-2006-3113, CVE-2006-3802, CVE-2006-3803, CVE-2006-3804, CVE-2006-3805, CVE-2006-3806, CVE-2006-3807, CVE-2006-3808, CVE-2006-3809, CVE-200
CVE-2006-3801 Multiple Thunderbird issues (CVE-2006-3677, CVE-2006-3113, CVE-2006-3802, CVE-2006-3803, CVE-2006-3804, CVE-2006-3805, CVE-2006-3806, CVE-2006-3807, CVE-2006-3808, CVE-2006-3809, CVE-2006-3810, CVE-2006-3811)
+++ This bug was initially created as a clone of Bug #200161 +++
Several Issues were discovered in Thunderbird, they are expected to be fixed in
the next upstream Seamonkey release
CVE-2006-3807 MFSA 2006-51
CVE-2006-3809 MFSA 2006-53
Several flaws were found in the way Thunderbird processes certain javascript
actions. A malicious web page could execute arbitrary javascript
instructions with the permissions of "chrome", allowing the page to steal
sensitive information or install browser malware.
CVE-2006-3801 MFSA 2006-44
CVE-2006-3677 MFSA 2006-45
CVE-2006-3113 MF
Bugzilla
CVE-2006-2779 Multiple Mozilla, Firefox issues (CVE-2006-2781, CVE-2006-2788)
bugzilla·2006-06-08·CVSS 9.3
CVE-2006-2779 [CRITICAL] CVE-2006-2779 Multiple Mozilla, Firefox issues (CVE-2006-2781, CVE-2006-2788)
CVE-2006-2779 Multiple Mozilla, Firefox issues (CVE-2006-2781, CVE-2006-2788)
+++ This bug was initially created as a clone of Bug #193906 +++
Text stolen from MITRE:
CVE-2006-2781
Double-free vulnerability in Mozilla Thunderbird before 1.5.0.4 and
SeaMonkey before 1.0.2 allows remote attackers to cause a denial of
service (hang) and possibly execute arbitrary code via a VCard that
contains invalid base64 characters.
CVE-2006-2779
Mozilla Firefox and Thunderbird before 1.5.0.4 allow remote attackers
to cause a denial of service (crash) and possibly execute arbitrary
code via (1) nested tags in a select tag, (2) a
DOMNodeRemoved mutation event, (3) "Content-implemented tree views,"
(4) BoxObjects, (5) the XBL implementation, (6) an iframe that
attempts to remove itself, which leads to m
ftp://patches.sgi.com/support/free/security/advisories/20060703-01-U.aschttp://rhn.redhat.com/errata/RHSA-2006-0609.htmlhttp://secunia.com/advisories/21228http://secunia.com/advisories/21229http://secunia.com/advisories/21246http://secunia.com/advisories/21250http://secunia.com/advisories/21262http://secunia.com/advisories/21269http://secunia.com/advisories/21275http://secunia.com/advisories/21336http://secunia.com/advisories/21343http://secunia.com/advisories/21358http://secunia.com/advisories/21529http://secunia.com/advisories/21532http://secunia.com/advisories/21607http://secunia.com/advisories/21631http://secunia.com/advisories/22055http://secunia.com/advisories/22065http://security.gentoo.org/glsa/glsa-200608-02.xmlhttp://security.gentoo.org/glsa/glsa-200608-04.xmlhttp://securitytracker.com/id?1016587http://securitytracker.com/id?1016588http://sunsolve.sun.com/search/document.do?assetkey=1-26-102763-1http://www.kb.cert.org/vuls/id/897540http://www.mandriva.com/security/advisories?name=MDKSA-2006:143http://www.mandriva.com/security/advisories?name=MDKSA-2006:145http://www.mandriva.com/security/advisories?name=MDKSA-2006:146http://www.mozilla.org/security/announce/2006/mfsa2006-49.htmlhttp://www.novell.com/linux/security/advisories/2006_48_seamonkey.htmlhttp://www.redhat.com/support/errata/RHSA-2006-0594.htmlhttp://www.redhat.com/support/errata/RHSA-2006-0608.htmlhttp://www.redhat.com/support/errata/RHSA-2006-0611.htmlhttp://www.securityfocus.com/archive/1/446657/100/200/threadedhttp://www.securityfocus.com/bid/19181http://www.ubuntu.com/usn/usn-350-1http://www.us-cert.gov/cas/techalerts/TA06-208A.htmlhttp://www.vupen.com/english/advisories/2006/2998http://www.vupen.com/english/advisories/2006/3749http://www.vupen.com/english/advisories/2007/0058https://exchange.xforce.ibmcloud.com/vulnerabilities/27985https://issues.rpath.com/browse/RPL-537https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11395https://usn.ubuntu.com/329-1/ftp://patches.sgi.com/support/free/security/advisories/20060703-01-U.aschttp://rhn.redhat.com/errata/RHSA-2006-0609.htmlhttp://secunia.com/advisories/21228http://secunia.com/advisories/21229http://secunia.com/advisories/21246http://secunia.com/advisories/21250http://secunia.com/advisories/21262http://secunia.com/advisories/21269http://secunia.com/advisories/21275http://secunia.com/advisories/21336http://secunia.com/advisories/21343http://secunia.com/advisories/21358http://secunia.com/advisories/21529http://secunia.com/advisories/21532http://secunia.com/advisories/21607http://secunia.com/advisories/21631http://secunia.com/advisories/22055http://secunia.com/advisories/22065http://security.gentoo.org/glsa/glsa-200608-02.xmlhttp://security.gentoo.org/glsa/glsa-200608-04.xmlhttp://securitytracker.com/id?1016587http://securitytracker.com/id?1016588http://sunsolve.sun.com/search/document.do?assetkey=1-26-102763-1http://www.kb.cert.org/vuls/id/897540http://www.mandriva.com/security/advisories?name=MDKSA-2006:143http://www.mandriva.com/security/advisories?name=MDKSA-2006:145http://www.mandriva.com/security/advisories?name=MDKSA-2006:146http://www.mozilla.org/security/announce/2006/mfsa2006-49.htmlhttp://www.novell.com/linux/security/advisories/2006_48_seamonkey.htmlhttp://www.redhat.com/support/errata/RHSA-2006-0594.htmlhttp://www.redhat.com/support/errata/RHSA-2006-0608.htmlhttp://www.redhat.com/support/errata/RHSA-2006-0611.htmlhttp://www.securityfocus.com/archive/1/446657/100/200/threadedhttp://www.securityfocus.com/bid/19181http://www.ubuntu.com/usn/usn-350-1http://www.us-cert.gov/cas/techalerts/TA06-208A.htmlhttp://www.vupen.com/english/advisories/2006/2998http://www.vupen.com/english/advisories/2006/3749http://www.vupen.com/english/advisories/2007/0058https://exchange.xforce.ibmcloud.com/vulnerabilities/27985https://issues.rpath.com/browse/RPL-537https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11395https://usn.ubuntu.com/329-1/
2006-07-27
Published