CVE-2006-4566Firefox vulnerability

12 documents7 sources
Severity
5.0MEDIUMNVD
EPSS
24.7%
top 3.85%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 15
Latest updateMay 3

Description

Mozilla Firefox before 1.5.0.7, Thunderbird before 1.5.0.7, and SeaMonkey before 1.0.5 allows remote attackers to cause a denial of service (crash) via a malformed JavaScript regular expression that ends with a backslash in an unterminated character set ("[\\"), which leads to a buffer over-read.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages6 packages

Debianmozilla/thunderbird< 1.5.0.7-1+3
NVDmozilla/firefox1.5.0.6
NVDmozilla/thunderbird1.5.0.6
debiandebian/firefox< firefox 1.5.dfsg+1.5.0.7-1 (sid)

Patches

🔴Vulnerability Details

2
GHSA
GHSA-vr27-vq6j-wvvp: Mozilla Firefox before 12022-05-03
OSV
CVE-2006-4566: Mozilla Firefox before 12006-09-15

📋Vendor Advisories

5
Ubuntu
Thunderbird vulnerabilities2006-09-25
Ubuntu
firefox vulnerabilities2006-09-23
Ubuntu
Thunderbird vulnerabilities2006-09-22
Red Hat
security flaw2006-09-15
Debian
CVE-2006-4566: firefox - Mozilla Firefox before 1.5.0.7, Thunderbird before 1.5.0.7, and SeaMonkey before...2006

💬Community

4
Bugzilla
CVE-2006-4566 security flaw2018-08-16
Bugzilla
CVE-2006-4340 Various SeaMonkey security issues (CVE-2006-4253 CVE-2006-4565 CVE-2006-4566 CVE-2006-4568 CVE-2006-4570 CVE-2006-4571)2006-09-14
Bugzilla
CVE-2006-4340 Various Firefox security issues (CVE-2006-4253 CVE-2006-4565 CVE-2006-4566 CVE-2006-4567 CVE-2006-4568 CVE-2006-4569 CVE-2006-4571)2006-09-14
Bugzilla
CVE-2006-4340 Various Thunderbird security issues (CVE-2006-4253 CVE-2006-4565 CVE-2006-4566 CVE-2006-4567 CVE-2006-4570 CVE-2006-4571)2006-09-14