CVE-2006-6505
published 2006-12-20CVE-2006-6505: Multiple heap-based buffer overflows in Mozilla Thunderbird before 1.5.0.9 and SeaMonkey before 1.0.7 allow remote attackers to execute arbitrary code via (1)…
PriorityP431medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
4.21%
89.8th percentile
Multiple heap-based buffer overflows in Mozilla Thunderbird before 1.5.0.9 and SeaMonkey before 1.0.7 allow remote attackers to execute arbitrary code via (1) external message modies with long Content-Type headers or (2) long RFC2047-encoded (MIME non-ASCII) headers.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | seamonkey | <= 1.0.6 | — |
| mozilla | thunderbird | <= 1.5.0.8 | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_redhat6.8MEDIUM
vendor_ubuntu6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2007-01-05·CVSS 6.8
CVE-2006-6505 [MEDIUM] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Thunderbird vulnerabilities
Georgi Guninski and David Bienvenu discovered that long Content-Type and
RFC2047-encoded headers we vulnerable to heap overflows. By tricking
the user into opening a specially crafted email, an attacker could
execute arbitrary code with user privileges. (CVE-2006-6506)
Various flaws have been reported that allow an attacker to execute
arbitrary code with user privileges or bypass internal XSS protections
by tricking the user into opening a malicious email containing
JavaScript. Please note that JavaScript is disabled by default for
emails, and it is not recommended to enable it. (CVE-2006-6497,
CVE-2006-6498, CVE-2006-6499, CVE-2006-6501, CVE-2006-6502,
CVE-2006-6503)
Instructions: After a standard system upgrade y
Red Hat
seamonkey < 1.0.7 multiple vulnerabilities
vendor_redhat·2006-12-19·CVSS 6.8
CVE-2006-6505 [MEDIUM] seamonkey < 1.0.7 multiple vulnerabilities
seamonkey < 1.0.7 multiple vulnerabilities
Multiple heap-based buffer overflows in Mozilla Thunderbird before 1.5.0.9 and SeaMonkey before 1.0.7 allow remote attackers to execute arbitrary code via (1) external message modies with long Content-Type headers or (2) long RFC2047-encoded (MIME non-ASCII) headers.
GHSA
GHSA-5v4r-m243-rv3w: Multiple heap-based buffer overflows in Mozilla Thunderbird before 1
ghsa_unreviewed·2022-05-03
CVE-2006-6505 [MEDIUM] GHSA-5v4r-m243-rv3w: Multiple heap-based buffer overflows in Mozilla Thunderbird before 1
Multiple heap-based buffer overflows in Mozilla Thunderbird before 1.5.0.9 and SeaMonkey before 1.0.7 allow remote attackers to execute arbitrary code via (1) external message modies with long Content-Type headers or (2) long RFC2047-encoded (MIME non-ASCII) headers.
No detection rules found.
No public exploits indexed.
Bugzilla
seamonkey < 1.0.7 multiple vulnerabilities
bugzilla·2006-12-21·CVSS 6.8
CVE-2006-6497 [MEDIUM] seamonkey < 1.0.7 multiple vulnerabilities
seamonkey < 1.0.7 multiple vulnerabilities
Vulnerabilities reported against seamonkey < 1.0.7:
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2006-6497
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2006-6498
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2006-6499
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2006-6500
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2006-6501
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2006-6502
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2006-6503
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2006-6504
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2006-6505
All FE4+ releases have < 1.0.7 at the moment.
By the way, seamonkey's CVS and package repository availability needs fixing,
the FC-5 branch in Extras CVS has been marked as dead with a comment that
seamonkey will be imported as a FC-5 (Core) update, b
Bugzilla
CVE-2006-6497 Multiple Thunderbird issues (CVE-2006-6498, CVE-2006-6501, CVE-2006-6502, CVE-2006-6503, CVE-2006-6504, CVE-2006-6505)
bugzilla·2006-12-14·CVSS 6.8
CVE-2006-6497 [MEDIUM] CVE-2006-6497 Multiple Thunderbird issues (CVE-2006-6498, CVE-2006-6501, CVE-2006-6502, CVE-2006-6503, CVE-2006-6504, CVE-2006-6505)
CVE-2006-6497 Multiple Thunderbird issues (CVE-2006-6498, CVE-2006-6501, CVE-2006-6502, CVE-2006-6503, CVE-2006-6504, CVE-2006-6505)
+++ This bug was initially created as a clone of Bug #219682 +++
The Mozilla project is releasing Firefox 1.5.0.9 to fix several flaws:
mfsa2006-68
impact=moderate,source=mozilla,reported=20061212,public=20061219
As part of the Firefox 2.0.0.1 and 1.5.0.9 update releases we fixed several
bugs to improve the stability of the product. Some of these were crashes
that showed evidence of memory corruption and we presume that at least some
of these could be exploited to run arbitrary code with enough effort.
CVE-2006-6497
Andrew Miller, David Baron, Georgi Guninski, Jesse Ruderman, Olli Pettay and
Vladimir Vukicevic reported crashes in the layout engine
CVE-2
Bugzilla
CVE-2006-6497 Multiple Seamonkey issues (CVE-2006-6498, CVE-2006-6501, CVE-2006-6502, CVE-2006-6503, CVE-2006-6504, CVE-2006-6505)
bugzilla·2006-12-14·CVSS 6.8
CVE-2006-6497 [MEDIUM] CVE-2006-6497 Multiple Seamonkey issues (CVE-2006-6498, CVE-2006-6501, CVE-2006-6502, CVE-2006-6503, CVE-2006-6504, CVE-2006-6505)
CVE-2006-6497 Multiple Seamonkey issues (CVE-2006-6498, CVE-2006-6501, CVE-2006-6502, CVE-2006-6503, CVE-2006-6504, CVE-2006-6505)
+++ This bug was initially created as a clone of Bug #219682 +++
The Mozilla project is releasing Firefox 1.5.0.9 to fix several flaws:
mfsa2006-68
impact=critical,source=mozilla,reported=20061212,public=20061219
As part of the Firefox 2.0.0.1 and 1.5.0.9 update releases we fixed several
bugs to improve the stability of the product. Some of these were crashes
that showed evidence of memory corruption and we presume that at least some
of these could be exploited to run arbitrary code with enough effort.
CVE-2006-6497
Andrew Miller, David Baron, Georgi Guninski, Jesse Ruderman, Olli Pettay and
Vladimir Vukicevic reported crashes in the layout engine
CVE-200
ftp://patches.sgi.com/support/free/security/advisories/20061202-01-P.aschttp://fedoranews.org/cms/node/2297http://fedoranews.org/cms/node/2338http://rhn.redhat.com/errata/RHSA-2006-0759.htmlhttp://rhn.redhat.com/errata/RHSA-2006-0760.htmlhttp://secunia.com/advisories/23420http://secunia.com/advisories/23422http://secunia.com/advisories/23433http://secunia.com/advisories/23439http://secunia.com/advisories/23468http://secunia.com/advisories/23514http://secunia.com/advisories/23545http://secunia.com/advisories/23591http://secunia.com/advisories/23598http://secunia.com/advisories/23601http://secunia.com/advisories/23618http://secunia.com/advisories/23672http://secunia.com/advisories/23692http://secunia.com/advisories/24108http://secunia.com/advisories/24390http://securitytracker.com/id?1017419http://securitytracker.com/id?1017420http://sunsolve.sun.com/search/document.do?assetkey=1-26-102800-1http://www.debian.org/security/2007/dsa-1265http://www.gentoo.org/security/en/glsa/glsa-200701-03.xmlhttp://www.gentoo.org/security/en/glsa/glsa-200701-04.xmlhttp://www.kb.cert.org/vuls/id/887332http://www.mandriva.com/security/advisories?name=MDKSA-2007:011http://www.mozilla.org/security/announce/2006/mfsa2006-74.htmlhttp://www.novell.com/linux/security/advisories/2006_80_mozilla.htmlhttp://www.novell.com/linux/security/advisories/2007_06_mozilla.htmlhttp://www.securityfocus.com/archive/1/455145/100/0/threadedhttp://www.securityfocus.com/archive/1/455728/100/200/threadedhttp://www.securityfocus.com/bid/21668http://www.ubuntu.com/usn/usn-400-1http://www.us-cert.gov/cas/techalerts/TA06-354A.htmlhttp://www.vupen.com/english/advisories/2006/5068http://www.vupen.com/english/advisories/2007/0573http://www.vupen.com/english/advisories/2008/0083https://issues.rpath.com/browse/RPL-883https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11565ftp://patches.sgi.com/support/free/security/advisories/20061202-01-P.aschttp://fedoranews.org/cms/node/2297http://fedoranews.org/cms/node/2338http://rhn.redhat.com/errata/RHSA-2006-0759.htmlhttp://rhn.redhat.com/errata/RHSA-2006-0760.htmlhttp://secunia.com/advisories/23420http://secunia.com/advisories/23422http://secunia.com/advisories/23433http://secunia.com/advisories/23439http://secunia.com/advisories/23468http://secunia.com/advisories/23514http://secunia.com/advisories/23545http://secunia.com/advisories/23591http://secunia.com/advisories/23598http://secunia.com/advisories/23601http://secunia.com/advisories/23618http://secunia.com/advisories/23672http://secunia.com/advisories/23692http://secunia.com/advisories/24108http://secunia.com/advisories/24390http://securitytracker.com/id?1017419http://securitytracker.com/id?1017420http://sunsolve.sun.com/search/document.do?assetkey=1-26-102800-1http://www.debian.org/security/2007/dsa-1265http://www.gentoo.org/security/en/glsa/glsa-200701-03.xmlhttp://www.gentoo.org/security/en/glsa/glsa-200701-04.xmlhttp://www.kb.cert.org/vuls/id/887332http://www.mandriva.com/security/advisories?name=MDKSA-2007:011http://www.mozilla.org/security/announce/2006/mfsa2006-74.htmlhttp://www.novell.com/linux/security/advisories/2006_80_mozilla.htmlhttp://www.novell.com/linux/security/advisories/2007_06_mozilla.htmlhttp://www.securityfocus.com/archive/1/455145/100/0/threadedhttp://www.securityfocus.com/archive/1/455728/100/200/threadedhttp://www.securityfocus.com/bid/21668http://www.ubuntu.com/usn/usn-400-1http://www.us-cert.gov/cas/techalerts/TA06-354A.htmlhttp://www.vupen.com/english/advisories/2006/5068http://www.vupen.com/english/advisories/2007/0573http://www.vupen.com/english/advisories/2008/0083https://issues.rpath.com/browse/RPL-883https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11565
2006-12-20
Published