CVE-2006-5462
published 2006-11-08CVE-2006-5462: Mozilla Network Security Service (NSS) library before 3.11.3, as used in Mozilla Firefox before 1.5.0.8, Thunderbird before 1.5.0.8, and SeaMonkey before…
PriorityP425medium6.4CVSS 2.0
AVNACLAuNCPIPAN
EPSS
2.63%
83.9th percentile
Mozilla Network Security Service (NSS) library before 3.11.3, as used in Mozilla Firefox before 1.5.0.8, Thunderbird before 1.5.0.8, and SeaMonkey before 1.0.6, when using an RSA key with exponent 3, does not properly handle extra data in a signature, which allows remote attackers to forge signatures for SSL/TLS and email certificates. NOTE: this identifier is for unpatched product versions that were originally intended to be addressed by CVE-2006-4340.
Affected
34 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | < firefox 1.5.dfsg+1.5.0.7-1 (sid) | firefox 1.5.dfsg+1.5.0.7-1 (sid) |
| debian | firefox | < firefox 45.0-1 (sid) | firefox 45.0-1 (sid) |
| debian | firefox-esr | < firefox 45.0-1 (sid) | firefox 45.0-1 (sid) |
| debian | thunderbird | < firefox 1.5.dfsg+1.5.0.7-1 (sid) | firefox 1.5.dfsg+1.5.0.7-1 (sid) |
| mozilla | firefox | <= 1.5.0.6 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | network_security_services | <= 3.11.2 | — |
| mozilla | network_security_services | — | — |
| mozilla | seamonkey | <= 1.0.4 | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | seamonkey | — | — |
| mozilla | thunderbird | <= 1.5.0.6 | — |
| mozilla | thunderbird | — | — |
| mozilla | thunderbird | — | — |
CVSS provenance
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
osv4.3MEDIUM
vendor_ubuntu6.4MEDIUM
vendor_debian4.3HIGH
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2006-11-21·CVSS 6.4
CVE-2006-5462 [MEDIUM] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox vulnerabilities
USN-351-1 fixed a flaw in the verification of PKCS certificate
signatures. Ulrich Kuehn discovered a variant of the original attack
which the original fix did not cover. (CVE-2006-5462)
Various flaws have been reported that allow an attacker to execute
arbitrary code with user privileges by tricking the user into opening
a malicious web page containing JavaScript. (CVE-2006-5463,
CVE-2006-5464, CVE-2006-5747, CVE-2006-5748)
Instructions: After a standard system upgrade you need to restart Firefox to
effect the necessary changes.
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2006-11-21·CVSS 6.4
CVE-2006-5462 [MEDIUM] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Thunderbird vulnerabilities
USN-352-1 fixed a flaw in the verification of PKCS certificate
signatures. Ulrich Kuehn discovered a variant of the original attack
which the original fix did not cover. (CVE-2006-5462)
Various flaws have been reported that allow an attacker to execute
arbitrary code with user privileges by tricking the user into opening a
malicious email containing JavaScript. Please note that JavaScript is
disabled by default for emails, and it is not recommended to enable it.
(CVE-2006-5463, CVE-2006-5464, CVE-2006-5747, CVE-2006-5748)
Instructions: After a standard system upgrade you need to restart Thunderbird to
effect the necessary changes.
Red Hat
security flaw
vendor_redhat·2006-11-08·CVSS 4.0
CVE-2006-5462 [MEDIUM] security flaw
security flaw
Mozilla Network Security Service (NSS) library before 3.11.3, as used in Mozilla Firefox before 1.5.0.8, Thunderbird before 1.5.0.8, and SeaMonkey before 1.0.6, when using an RSA key with exponent 3, does not properly handle extra data in a signature, which allows remote attackers to forge signatures for SSL/TLS and email certificates. NOTE: this identifier is for unpatched product versions that were originally intended to be addressed by CVE-2006-4340.
Red Hat
security flaw
vendor_redhat·2006-09-15·CVSS 4.3
CVE-2006-4340 [MEDIUM] security flaw
security flaw
Mozilla Network Security Service (NSS) library before 3.11.3, as used in Mozilla Firefox before 1.5.0.7, Thunderbird before 1.5.0.7, and SeaMonkey before 1.0.5, when using an RSA key with exponent 3, does not properly handle extra data in a signature, which allows remote attackers to forge signatures for SSL/TLS and email certificates, a similar vulnerability to CVE-2006-4339. NOTE: on 20061107, Mozilla released an advisory stating that these versions were not completely patched by MFSA2006-60. The newer fixes for 1.5.0.7 are covered by CVE-2006-5462.
Debian
CVE-2006-4340: firefox - Mozilla Network Security Service (NSS) library before 3.11.3, as used in Mozilla...
vendor_debian·2006·CVSS 4.3
CVE-2006-4340 [MEDIUM] CVE-2006-4340: firefox - Mozilla Network Security Service (NSS) library before 3.11.3, as used in Mozilla...
Mozilla Network Security Service (NSS) library before 3.11.3, as used in Mozilla Firefox before 1.5.0.7, Thunderbird before 1.5.0.7, and SeaMonkey before 1.0.5, when using an RSA key with exponent 3, does not properly handle extra data in a signature, which allows remote attackers to forge signatures for SSL/TLS and email certificates, a similar vulnerability to CVE-2006-4339. NOTE: on 20061107, Mozilla released an advisory stating that these versions were not completely patched by MFSA2006-60. The newer fixes for 1.5.0.7 are covered by CVE-2006-5462.
Scope: local
sid: resolved (fixed in 1.5.dfsg+1.5.0.7-1)
Debian
CVE-2006-5462: firefox - Mozilla Network Security Service (NSS) library before 3.11.3, as used in Mozilla...
vendor_debian·2006·CVSS 4.0
CVE-2006-5462 [MEDIUM] CVE-2006-5462: firefox - Mozilla Network Security Service (NSS) library before 3.11.3, as used in Mozilla...
Mozilla Network Security Service (NSS) library before 3.11.3, as used in Mozilla Firefox before 1.5.0.8, Thunderbird before 1.5.0.8, and SeaMonkey before 1.0.6, when using an RSA key with exponent 3, does not properly handle extra data in a signature, which allows remote attackers to forge signatures for SSL/TLS and email certificates. NOTE: this identifier is for unpatched product versions that were originally intended to be addressed by CVE-2006-4340.
Scope: local
sid: resolved (fixed in 45.0-1)
VulDB
Mozilla Firefox up to 1.5.0.7 XML.prototype.hasOwnProperty Remote Code Execution (MFSA2006-65 / VU#335392)
vuldb·2026-04-27·CVSS 6.4
CVE-2006-5462 [MEDIUM] Mozilla Firefox up to 1.5.0.7 XML.prototype.hasOwnProperty Remote Code Execution (MFSA2006-65 / VU#335392)
A vulnerability was found in Mozilla Firefox up to 1.5.0.7. It has been classified as critical. This vulnerability affects the function XML.prototype.hasOwnProperty. This manipulation causes Remote Code Execution.
This vulnerability is registered as CVE-2006-5462. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is recommended.
VulDB
Mozilla Firefox up to 1.5.0.7 Javascript Script Modificator (MFSA2006-67 / VU#335392)
vuldb·2026-04-27·CVSS 6.4
CVE-2006-5462 [MEDIUM] Mozilla Firefox up to 1.5.0.7 Javascript Script Modificator (MFSA2006-67 / VU#335392)
A vulnerability has been found in Mozilla Firefox up to 1.5.0.7 and classified as critical. Affected by this issue is some unknown functionality of the component Javascript Script Modificator. The manipulation leads to an unknown weakness.
This vulnerability is listed as CVE-2006-5462. The attack may be initiated remotely. There is no available exploit.
The affected component should be upgraded.
GHSA
GHSA-q7vf-rjwh-chxv: Mozilla Network Security Service (NSS) library before 3
ghsa_unreviewed·2022-05-03·CVSS 4.3
CVE-2006-4340 [MEDIUM] CWE-20 GHSA-q7vf-rjwh-chxv: Mozilla Network Security Service (NSS) library before 3
Mozilla Network Security Service (NSS) library before 3.11.3, as used in Mozilla Firefox before 1.5.0.7, Thunderbird before 1.5.0.7, and SeaMonkey before 1.0.5, when using an RSA key with exponent 3, does not properly handle extra data in a signature, which allows remote attackers to forge signatures for SSL/TLS and email certificates, a similar vulnerability to CVE-2006-4339. NOTE: on 20061107, Mozilla released an advisory stating that these versions were not completely patched by MFSA2006-60. The newer fixes for 1.5.0.7 are covered by CVE-2006-5462.
GHSA
GHSA-rmhr-q7w5-3ffq: Mozilla Network Security Service (NSS) library before 3
ghsa_unreviewed·2022-05-03·CVSS 4.0
CVE-2006-5462 [MEDIUM] GHSA-rmhr-q7w5-3ffq: Mozilla Network Security Service (NSS) library before 3
Mozilla Network Security Service (NSS) library before 3.11.3, as used in Mozilla Firefox before 1.5.0.8, Thunderbird before 1.5.0.8, and SeaMonkey before 1.0.6, when using an RSA key with exponent 3, does not properly handle extra data in a signature, which allows remote attackers to forge signatures for SSL/TLS and email certificates. NOTE: this identifier is for unpatched product versions that were originally intended to be addressed by CVE-2006-4340.
OSV
CVE-2006-5462: Mozilla Network Security Service (NSS) library before 3
osv·2006-11-08·CVSS 4.0
CVE-2006-5462 [MEDIUM] CVE-2006-5462: Mozilla Network Security Service (NSS) library before 3
Mozilla Network Security Service (NSS) library before 3.11.3, as used in Mozilla Firefox before 1.5.0.8, Thunderbird before 1.5.0.8, and SeaMonkey before 1.0.6, when using an RSA key with exponent 3, does not properly handle extra data in a signature, which allows remote attackers to forge signatures for SSL/TLS and email certificates. NOTE: this identifier is for unpatched product versions that were originally intended to be addressed by CVE-2006-4340.
OSV
CVE-2006-4340: Mozilla Network Security Service (NSS) library before 3
osv·2006-09-15·CVSS 4.3
CVE-2006-4340 [MEDIUM] CVE-2006-4340: Mozilla Network Security Service (NSS) library before 3
Mozilla Network Security Service (NSS) library before 3.11.3, as used in Mozilla Firefox before 1.5.0.7, Thunderbird before 1.5.0.7, and SeaMonkey before 1.0.5, when using an RSA key with exponent 3, does not properly handle extra data in a signature, which allows remote attackers to forge signatures for SSL/TLS and email certificates, a similar vulnerability to CVE-2006-4339. NOTE: on 20061107, Mozilla released an advisory stating that these versions were not completely patched by MFSA2006-60. The newer fixes for 1.5.0.7 are covered by CVE-2006-5462.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2006-4340 security flaw
bugzilla·2018-08-16·CVSS 4.3
CVE-2006-4340 [MEDIUM] CVE-2006-4340 security flaw
CVE-2006-4340 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
Mozilla Network Security Service (NSS) library before 3.11.3, as used in Mozilla Firefox before 1.5.0.7, Thunderbird before 1.5.0.7, and SeaMonkey before 1.0.5, when using an RSA key with exponent 3, does not properly handle extra data in a signature, which allows remote attackers to forge signatures for SSL/TLS and email certificates, a similar vulnerability to CVE-2006-4339. NOTE: on 20061107, Mozilla released an advisory stating that these versions were not completely patched by MFSA2006-60. The newer fixes for 1.5.0.7 are covered by CVE-2006-5462.
Bugzilla
CVE-2006-5462 security flaw
bugzilla·2018-08-16·CVSS 4.0
CVE-2006-5462 [MEDIUM] CVE-2006-5462 security flaw
CVE-2006-5462 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
Mozilla Network Security Service (NSS) library before 3.11.3, as used in Mozilla Firefox before 1.5.0.8, Thunderbird before 1.5.0.8, and SeaMonkey before 1.0.6, when using an RSA key with exponent 3, does not properly handle extra data in a signature, which allows remote attackers to forge signatures for SSL/TLS and email certificates. NOTE: this identifier is for unpatched product versions that were originally intended to be addressed by CVE-2006-4340.
Bugzilla
CVE-2006-5462 Multiple thunderbird vulnerabilities (CVE-2006-5463, CVE-2006-5464, CVE-2006-5747, CVE-2006-5748)
bugzilla·2006-11-07·CVSS 6.4
CVE-2006-5462 [MEDIUM] CVE-2006-5462 Multiple thunderbird vulnerabilities (CVE-2006-5463, CVE-2006-5464, CVE-2006-5747, CVE-2006-5748)
CVE-2006-5462 Multiple thunderbird vulnerabilities (CVE-2006-5463, CVE-2006-5464, CVE-2006-5747, CVE-2006-5748)
+++ This bug was initially created as a clone of Bug #214445 +++
The Mozilla project is releasing Thunderbird 1.5.0.8 to fix a number of security
flaws (Text taken from the upstream advisories):
mfsa2006-66
CVE-2006-5462
impact=important,reported=20061107,public=20061107,source=mozilla
MFSA 2006-60 reported that RSA digital signatures with a low exponent
(typically 3) could be forged, and that this flaw was corrected in the
Mozilla Network Security Services (NSS) library version 3.11.3 used by
Firefox 2.0 and current development versions of Mozilla clients.
Ulrich Kuehn reported that Firefox 1.5.0.7, which incorporated NSS version
3.10.2, was incompletely patched and remaine
Bugzilla
CVE-2006-5462 Multiple firefox vulnerabilities (CVE-2006-5463, CVE-2006-5464, CVE-2006-5747, CVE-2006-5748)
bugzilla·2006-11-07·CVSS 6.4
CVE-2006-5462 [MEDIUM] CVE-2006-5462 Multiple firefox vulnerabilities (CVE-2006-5463, CVE-2006-5464, CVE-2006-5747, CVE-2006-5748)
CVE-2006-5462 Multiple firefox vulnerabilities (CVE-2006-5463, CVE-2006-5464, CVE-2006-5747, CVE-2006-5748)
The Mozilla project is releasing Firefox 1.5.0.8 to fix a number of security
flaws (Text taken from the upstream advisories):
mfsa2006-66
CVE-2006-5462
impact=important,reported=20061107,public=20061107,source=mozilla
MFSA 2006-60 reported that RSA digital signatures with a low exponent
(typically 3) could be forged, and that this flaw was corrected in the
Mozilla Network Security Services (NSS) library version 3.11.3 used by
Firefox 2.0 and current development versions of Mozilla clients.
Ulrich Kuehn reported that Firefox 1.5.0.7, which incorporated NSS version
3.10.2, was incompletely patched and remained vulnerable to a variant of
this attack.
mfsa2006-67
CVE-2006-5463
impac
Bugzilla
CVE-2006-5462 Multiple seamonkey vulnerabilities (CVE-2006-5463, CVE-2006-5464, CVE-2006-5747, CVE-2006-5748)
bugzilla·2006-11-07·CVSS 6.4
CVE-2006-5462 [MEDIUM] CVE-2006-5462 Multiple seamonkey vulnerabilities (CVE-2006-5463, CVE-2006-5464, CVE-2006-5747, CVE-2006-5748)
CVE-2006-5462 Multiple seamonkey vulnerabilities (CVE-2006-5463, CVE-2006-5464, CVE-2006-5747, CVE-2006-5748)
+++ This bug was initially created as a clone of Bug #214445 +++
Seamonkey 1.0.6 is being released to fix a number of security flaws (Text taken
from the upstream advisories):
mfsa2006-66
CVE-2006-5462
impact=important,reported=20061107,public=20061107,source=mozilla
MFSA 2006-60 reported that RSA digital signatures with a low exponent
(typically 3) could be forged, and that this flaw was corrected in the
Mozilla Network Security Services (NSS) library version 3.11.3 used by
Firefox 2.0 and current development versions of Mozilla clients.
Ulrich Kuehn reported that Firefox 1.5.0.7, which incorporated NSS version
3.10.2, was incompletely patched and remained vulnerable to a var
ftp://patches.sgi.com/support/free/security/advisories/20061101-01-Phttp://rhn.redhat.com/errata/RHSA-2006-0733.htmlhttp://rhn.redhat.com/errata/RHSA-2006-0734.htmlhttp://rhn.redhat.com/errata/RHSA-2006-0735.htmlhttp://secunia.com/advisories/22066http://secunia.com/advisories/22722http://secunia.com/advisories/22727http://secunia.com/advisories/22737http://secunia.com/advisories/22763http://secunia.com/advisories/22770http://secunia.com/advisories/22815http://secunia.com/advisories/22817http://secunia.com/advisories/22929http://secunia.com/advisories/22965http://secunia.com/advisories/22980http://secunia.com/advisories/23009http://secunia.com/advisories/23013http://secunia.com/advisories/23197http://secunia.com/advisories/23202http://secunia.com/advisories/23235http://secunia.com/advisories/23263http://secunia.com/advisories/23287http://secunia.com/advisories/23297http://secunia.com/advisories/23883http://secunia.com/advisories/24711http://security.gentoo.org/glsa/glsa-200612-06.xmlhttp://security.gentoo.org/glsa/glsa-200612-07.xmlhttp://security.gentoo.org/glsa/glsa-200612-08.xmlhttp://securitytracker.com/id?1017180http://securitytracker.com/id?1017181http://securitytracker.com/id?1017182http://sunsolve.sun.com/search/document.do?assetkey=1-26-102781-1http://support.avaya.com/elmodocs2/security/ASA-2006-246.htmhttp://www.debian.org/security/2006/dsa-1224http://www.debian.org/security/2006/dsa-1225http://www.debian.org/security/2006/dsa-1227http://www.kb.cert.org/vuls/id/335392http://www.mandriva.com/security/advisories?name=MDKSA-2006:205http://www.mandriva.com/security/advisories?name=MDKSA-2006:206http://www.mozilla.org/security/announce/2006/mfsa2006-60.htmlhttp://www.mozilla.org/security/announce/2006/mfsa2006-66.htmlhttp://www.novell.com/linux/security/advisories/2006_68_mozilla.htmlhttp://www.ubuntu.com/usn/usn-381-1http://www.ubuntu.com/usn/usn-382-1http://www.us-cert.gov/cas/techalerts/TA06-312A.htmlhttp://www.vupen.com/english/advisories/2006/3748http://www.vupen.com/english/advisories/2006/4387http://www.vupen.com/english/advisories/2007/0293http://www.vupen.com/english/advisories/2007/1198http://www.vupen.com/english/advisories/2008/0083http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00771742https://bugzilla.mozilla.org/show_bug.cgi?id=356215https://exchange.xforce.ibmcloud.com/vulnerabilities/30098https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10478ftp://patches.sgi.com/support/free/security/advisories/20061101-01-Phttp://rhn.redhat.com/errata/RHSA-2006-0733.htmlhttp://rhn.redhat.com/errata/RHSA-2006-0734.htmlhttp://rhn.redhat.com/errata/RHSA-2006-0735.htmlhttp://secunia.com/advisories/22066http://secunia.com/advisories/22722http://secunia.com/advisories/22727http://secunia.com/advisories/22737http://secunia.com/advisories/22763http://secunia.com/advisories/22770http://secunia.com/advisories/22815http://secunia.com/advisories/22817http://secunia.com/advisories/22929http://secunia.com/advisories/22965http://secunia.com/advisories/22980http://secunia.com/advisories/23009http://secunia.com/advisories/23013http://secunia.com/advisories/23197http://secunia.com/advisories/23202http://secunia.com/advisories/23235http://secunia.com/advisories/23263http://secunia.com/advisories/23287http://secunia.com/advisories/23297http://secunia.com/advisories/23883http://secunia.com/advisories/24711http://security.gentoo.org/glsa/glsa-200612-06.xmlhttp://security.gentoo.org/glsa/glsa-200612-07.xmlhttp://security.gentoo.org/glsa/glsa-200612-08.xmlhttp://securitytracker.com/id?1017180http://securitytracker.com/id?1017181http://securitytracker.com/id?1017182http://sunsolve.sun.com/search/document.do?assetkey=1-26-102781-1http://support.avaya.com/elmodocs2/security/ASA-2006-246.htmhttp://www.debian.org/security/2006/dsa-1224http://www.debian.org/security/2006/dsa-1225http://www.debian.org/security/2006/dsa-1227http://www.kb.cert.org/vuls/id/335392http://www.mandriva.com/security/advisories?name=MDKSA-2006:205http://www.mandriva.com/security/advisories?name=MDKSA-2006:206http://www.mozilla.org/security/announce/2006/mfsa2006-60.htmlhttp://www.mozilla.org/security/announce/2006/mfsa2006-66.htmlhttp://www.novell.com/linux/security/advisories/2006_68_mozilla.htmlhttp://www.ubuntu.com/usn/usn-381-1http://www.ubuntu.com/usn/usn-382-1http://www.us-cert.gov/cas/techalerts/TA06-312A.htmlhttp://www.vupen.com/english/advisories/2006/3748
+ 8 more references
2006-11-08
Published