CVE-2006-5654
published 2006-11-03CVE-2006-5654: Unspecified vulnerability in the Network Security Services (NSS) in Sun Java System Web Server 6.0 before SP 10 and ONE Application Server 7 before Update 3…
PriorityP412medium4CVSS 2.0
AVNACLAuSCNINAP
EPSS
2.04%
79.0th percentile
Unspecified vulnerability in the Network Security Services (NSS) in Sun Java System Web Server 6.0 before SP 10 and ONE Application Server 7 before Update 3, when SSLv2 is enabled, allows remote authenticated users to cause a denial of service (application crash) via unspecified vectors. NOTE: due to lack of details from the vendor, it is unclear whether this is related to vector 1 in CVE-2006-5201 or CVE-2006-3127.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sun | java_system_web_server | — | — |
| sun | one_application_server | <= 7.0 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Sun Java System Application Server up to 7.3 SSLv2 Network Security Services denial of service (XFDB-29946 / BID-20846)
vuldb·2026-04-26·CVSS 4.0
CVE-2006-5654 [MEDIUM] Sun Java System Application Server up to 7.3 SSLv2 Network Security Services denial of service (XFDB-29946 / BID-20846)
A vulnerability, which was classified as problematic, has been found in Sun Java System Application Server up to 7.3. The impacted element is an unknown function of the component SSLv2 Network Security Services. This manipulation causes denial of service.
This vulnerability is tracked as CVE-2006-5654. The attack is possible to be carried out remotely. No exploit exists.
It is recommended to apply a patch to fix this issue.
GHSA
GHSA-675c-9rfr-crmc: Unspecified vulnerability in the Network Security Services (NSS) in Sun Java System Web Server 6
ghsa_unreviewed·2022-05-01·CVSS 7.8
CVE-2006-5654 [HIGH] GHSA-675c-9rfr-crmc: Unspecified vulnerability in the Network Security Services (NSS) in Sun Java System Web Server 6
Unspecified vulnerability in the Network Security Services (NSS) in Sun Java System Web Server 6.0 before SP 10 and ONE Application Server 7 before Update 3, when SSLv2 is enabled, allows remote authenticated users to cause a denial of service (application crash) via unspecified vectors. NOTE: due to lack of details from the vendor, it is unclear whether this is related to vector 1 in CVE-2006-5201 or CVE-2006-3127.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/22646http://securitytracker.com/id?1017143http://sunsolve.sun.com/search/document.do?assetkey=1-26-102670-1http://www.securityfocus.com/bid/20846http://www.vupen.com/english/advisories/2006/4299https://exchange.xforce.ibmcloud.com/vulnerabilities/29946http://secunia.com/advisories/22646http://securitytracker.com/id?1017143http://sunsolve.sun.com/search/document.do?assetkey=1-26-102670-1http://www.securityfocus.com/bid/20846http://www.vupen.com/english/advisories/2006/4299https://exchange.xforce.ibmcloud.com/vulnerabilities/29946
2006-11-03
Published