CVE-2006-6500
published 2006-12-20CVE-2006-6500: Heap-based buffer overflow in Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote…
PriorityP335medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
8.29%
94.3th percentile
Heap-based buffer overflow in Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by setting the CSS cursor to certain images that cause an incorrect size calculation when converting to a Windows bitmap.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | firefox | — | — |
| mozilla | firefox | >= 1.5 < 1.5.0.9 | 1.5.0.9 |
| mozilla | firefox | >= 2.0 < 2.0.0.1 | 2.0.0.1 |
| mozilla | seamonkey | < 1.0.7 | 1.0.7 |
| mozilla | thunderbird | < 1.5.0.9 | 1.5.0.9 |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_debian6.8LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-59wr-4mm2-55f2: Heap-based buffer overflow in Mozilla Firefox 2
ghsa_unreviewed·2022-05-01
CVE-2006-6500 [MEDIUM] CWE-119 GHSA-59wr-4mm2-55f2: Heap-based buffer overflow in Mozilla Firefox 2
Heap-based buffer overflow in Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by setting the CSS cursor to certain images that cause an incorrect size calculation when converting to a Windows bitmap.
Debian
CVE-2006-6500: firefox - Heap-based buffer overflow in Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1...
vendor_debian·2006·CVSS 6.8
CVE-2006-6500 [MEDIUM] CVE-2006-6500: firefox - Heap-based buffer overflow in Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1...
Heap-based buffer overflow in Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by setting the CSS cursor to certain images that cause an incorrect size calculation when converting to a Windows bitmap.
Scope: local
sid: resolved
No detection rules found.
No public exploits indexed.
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742http://secunia.com/advisories/23282http://secunia.com/advisories/23420http://secunia.com/advisories/23422http://secunia.com/advisories/23545http://secunia.com/advisories/23598http://secunia.com/advisories/23614http://secunia.com/advisories/23672http://secunia.com/advisories/23692http://security.gentoo.org/glsa/glsa-200701-02.xmlhttp://securitytracker.com/id?1017399http://securitytracker.com/id?1017400http://securitytracker.com/id?1017401http://www.gentoo.org/security/en/glsa/glsa-200701-03.xmlhttp://www.gentoo.org/security/en/glsa/glsa-200701-04.xmlhttp://www.kb.cert.org/vuls/id/722244http://www.mandriva.com/security/advisories?name=MDKSA-2007:010http://www.mandriva.com/security/advisories?name=MDKSA-2007:011http://www.mozilla.org/security/announce/2006/mfsa2006-69.htmlhttp://www.novell.com/linux/security/advisories/2006_80_mozilla.htmlhttp://www.novell.com/linux/security/advisories/2007_06_mozilla.htmlhttp://www.securityfocus.com/bid/21668http://www.us-cert.gov/cas/techalerts/TA06-354A.htmlhttp://www.vupen.com/english/advisories/2006/5068http://www.vupen.com/english/advisories/2008/0083http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742http://secunia.com/advisories/23282http://secunia.com/advisories/23420http://secunia.com/advisories/23422http://secunia.com/advisories/23545http://secunia.com/advisories/23598http://secunia.com/advisories/23614http://secunia.com/advisories/23672http://secunia.com/advisories/23692http://security.gentoo.org/glsa/glsa-200701-02.xmlhttp://securitytracker.com/id?1017399http://securitytracker.com/id?1017400http://securitytracker.com/id?1017401http://www.gentoo.org/security/en/glsa/glsa-200701-03.xmlhttp://www.gentoo.org/security/en/glsa/glsa-200701-04.xmlhttp://www.kb.cert.org/vuls/id/722244http://www.mandriva.com/security/advisories?name=MDKSA-2007:010http://www.mandriva.com/security/advisories?name=MDKSA-2007:011http://www.mozilla.org/security/announce/2006/mfsa2006-69.htmlhttp://www.novell.com/linux/security/advisories/2006_80_mozilla.htmlhttp://www.novell.com/linux/security/advisories/2007_06_mozilla.htmlhttp://www.securityfocus.com/bid/21668http://www.us-cert.gov/cas/techalerts/TA06-354A.htmlhttp://www.vupen.com/english/advisories/2006/5068http://www.vupen.com/english/advisories/2008/0083
2006-12-20
Published