CVE-2006-5201
published 2006-10-10CVE-2006-5201: Multiple packages on Sun Solaris, including (1) NSS; (2) Java JDK and JRE 5.0 Update 8 and earlier, SDK and JRE 1.4.x up to 1.4.2_12, and SDK and JRE 1.3.x up…
PriorityP420medium4CVSS 2.0
AVNACHAuNCNIPAP
EPSS
3.16%
86.5th percentile
Multiple packages on Sun Solaris, including (1) NSS; (2) Java JDK and JRE 5.0 Update 8 and earlier, SDK and JRE 1.4.x up to 1.4.2_12, and SDK and JRE 1.3.x up to 1.3.1_19; (3) JSSE 1.0.3_03 and earlier; (4) IPSec/IKE; (5) Secure Global Desktop; and (6) StarOffice, when using an RSA key with exponent 3, removes PKCS-1 padding before generating a hash, which allows remote attackers to forge a PKCS #1 v1.5 signature that is signed by that RSA key and prevents these products from correctly verifying X.509 and other certificates that use PKCS #1.
Affected
79 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| sun | java_system_web_server | — | — |
| sun | jdk | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:H/Au:N/C:N/I:P/A:P
vendor_msrc4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Sun JRE 1.3.1/1.4.2/1.5.0 Certificates (VU#845620 / Nessus ID 22716)
vuldb·2026-04-23·CVSS 4.0
CVE-2006-5201 [MEDIUM] Sun JRE 1.3.1/1.4.2/1.5.0 Certificates (VU#845620 / Nessus ID 22716)
A vulnerability categorized as problematic has been discovered in Sun JRE 1.3.1/1.4.2/1.5.0. This affects an unknown function of the component Certificates. Executing a manipulation can lead to an unknown weakness.
This vulnerability is handled as CVE-2006-5201. The attack can be executed remotely. There is not any exploit available.
It is advisable to upgrade the affected component.
GHSA
GHSA-6xx2-gv3f-2f93: Multiple packages on Sun Solaris, including (1) NSS; (2) Java JDK and JRE 5
ghsa_unreviewed·2022-05-01
CVE-2006-5201 [MEDIUM] GHSA-6xx2-gv3f-2f93: Multiple packages on Sun Solaris, including (1) NSS; (2) Java JDK and JRE 5
Multiple packages on Sun Solaris, including (1) NSS; (2) Java JDK and JRE 5.0 Update 8 and earlier, SDK and JRE 1.4.x up to 1.4.2_12, and SDK and JRE 1.3.x up to 1.3.1_19; (3) JSSE 1.0.3_03 and earlier; (4) IPSec/IKE; (5) Secure Global Desktop; and (6) StarOffice, when using an RSA key with exponent 3, removes PKCS-1 padding before generating a hash, which allows remote attackers to forge a PKCS #1 v1.5 signature that is signed by that RSA key and prevents these products from correctly verifying X.509 and other certificates that use PKCS #1.
GHSA
GHSA-675c-9rfr-crmc: Unspecified vulnerability in the Network Security Services (NSS) in Sun Java System Web Server 6
ghsa_unreviewed·2022-05-01·CVSS 7.8
CVE-2006-5654 [HIGH] GHSA-675c-9rfr-crmc: Unspecified vulnerability in the Network Security Services (NSS) in Sun Java System Web Server 6
Unspecified vulnerability in the Network Security Services (NSS) in Sun Java System Web Server 6.0 before SP 10 and ONE Application Server 7 before Update 3, when SSLv2 is enabled, allows remote authenticated users to cause a denial of service (application crash) via unspecified vectors. NOTE: due to lack of details from the vendor, it is unclear whether this is related to vector 1 in CVE-2006-5201 or CVE-2006-3127.
Microsoft
CVE-2006-5201: NIST NVD Details: https://nvd
vendor_msrc·2020-09-08·CVSS 4.0
CVE-2006-5201 [MEDIUM] CVE-2006-5201: NIST NVD Details: https://nvd
NIST NVD Details: https://nvd.nist.gov/vuln/detail/CVE-2006-5201
Mariner: Mariner
[email protected]: [email protected]
Exploit Status: DOS:N/A
Remediation: nss
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/22204http://secunia.com/advisories/22226http://secunia.com/advisories/22325http://secunia.com/advisories/22992http://sunsolve.sun.com/search/document.do?assetkey=1-26-102648-1http://sunsolve.sun.com/search/document.do?assetkey=1-26-102657-1http://support.avaya.com/elmodocs2/security/ASA-2006-250.htmhttp://www.kb.cert.org/vuls/id/845620http://www.vupen.com/english/advisories/2006/3898http://www.vupen.com/english/advisories/2006/3899http://www.vupen.com/english/advisories/2006/3960http://secunia.com/advisories/22204http://secunia.com/advisories/22226http://secunia.com/advisories/22325http://secunia.com/advisories/22992http://sunsolve.sun.com/search/document.do?assetkey=1-26-102648-1http://sunsolve.sun.com/search/document.do?assetkey=1-26-102657-1http://support.avaya.com/elmodocs2/security/ASA-2006-250.htmhttp://www.kb.cert.org/vuls/id/845620http://www.vupen.com/english/advisories/2006/3898http://www.vupen.com/english/advisories/2006/3899http://www.vupen.com/english/advisories/2006/3960
2006-10-10
Published