CVE-2006-1730
Mozilla Firefox CSS Letter-Spacing Heap Overflow Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Integer overflow in Mozilla Firefox and Thunderbird 1.x before 1.5.0.2 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0.1 allows remote attackers to execute arbitrary code via a large number in the CSS letter-spacing property that leads to a heap-based buffer overflow.
This vulnerability allows attackers to execute arbitrary code on vulnerable installations of the Mozilla/Firefox web browser and Thunderbird e-mail client. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious e-mail.
The specific flaw is due to incorrect handling of the CSS "letter-spacing" element. By specifying a large number, an attacker can overflow an integer used during memory allocation. The under-allocated buffer is later used to store user-supplied data leading to an exploitable heap overflow.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2006-04-12 CVE Reserved
- 2006-04-14 CVE Published
- 2024-08-03 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-189: Numeric Errors
CAPEC
References (75)
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/19631 | 2018-10-18 | |
http://secunia.com/advisories/19649 | 2018-10-18 | |
http://securitytracker.com/id?1015915 | 2018-10-18 | |
http://securitytracker.com/id?1015916 | 2018-10-18 | |
http://securitytracker.com/id?1015917 | 2018-10-18 | |
http://securitytracker.com/id?1015918 | 2018-10-18 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Mozilla Search vendor "Mozilla" | Firefox Search vendor "Mozilla" for product "Firefox" | 1.0 Search vendor "Mozilla" for product "Firefox" and version "1.0" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Firefox Search vendor "Mozilla" for product "Firefox" | 1.0.1 Search vendor "Mozilla" for product "Firefox" and version "1.0.1" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Firefox Search vendor "Mozilla" for product "Firefox" | 1.0.2 Search vendor "Mozilla" for product "Firefox" and version "1.0.2" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Firefox Search vendor "Mozilla" for product "Firefox" | 1.0.3 Search vendor "Mozilla" for product "Firefox" and version "1.0.3" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Firefox Search vendor "Mozilla" for product "Firefox" | 1.0.4 Search vendor "Mozilla" for product "Firefox" and version "1.0.4" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Firefox Search vendor "Mozilla" for product "Firefox" | 1.0.5 Search vendor "Mozilla" for product "Firefox" and version "1.0.5" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Firefox Search vendor "Mozilla" for product "Firefox" | 1.0.6 Search vendor "Mozilla" for product "Firefox" and version "1.0.6" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Firefox Search vendor "Mozilla" for product "Firefox" | 1.0.7 Search vendor "Mozilla" for product "Firefox" and version "1.0.7" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Firefox Search vendor "Mozilla" for product "Firefox" | 1.5 Search vendor "Mozilla" for product "Firefox" and version "1.5" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Firefox Search vendor "Mozilla" for product "Firefox" | 1.5 Search vendor "Mozilla" for product "Firefox" and version "1.5" | beta1 |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Firefox Search vendor "Mozilla" for product "Firefox" | 1.5 Search vendor "Mozilla" for product "Firefox" and version "1.5" | beta2 |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Firefox Search vendor "Mozilla" for product "Firefox" | 1.5.0.1 Search vendor "Mozilla" for product "Firefox" and version "1.5.0.1" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Mozilla Suite Search vendor "Mozilla" for product "Mozilla Suite" | 1.7.6 Search vendor "Mozilla" for product "Mozilla Suite" and version "1.7.6" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Mozilla Suite Search vendor "Mozilla" for product "Mozilla Suite" | 1.7.7 Search vendor "Mozilla" for product "Mozilla Suite" and version "1.7.7" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Mozilla Suite Search vendor "Mozilla" for product "Mozilla Suite" | 1.7.8 Search vendor "Mozilla" for product "Mozilla Suite" and version "1.7.8" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Mozilla Suite Search vendor "Mozilla" for product "Mozilla Suite" | 1.7.10 Search vendor "Mozilla" for product "Mozilla Suite" and version "1.7.10" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Mozilla Suite Search vendor "Mozilla" for product "Mozilla Suite" | 1.7.11 Search vendor "Mozilla" for product "Mozilla Suite" and version "1.7.11" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Mozilla Suite Search vendor "Mozilla" for product "Mozilla Suite" | 1.7.12 Search vendor "Mozilla" for product "Mozilla Suite" and version "1.7.12" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Seamonkey Search vendor "Mozilla" for product "Seamonkey" | 1.0 Search vendor "Mozilla" for product "Seamonkey" and version "1.0" | alpha |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Seamonkey Search vendor "Mozilla" for product "Seamonkey" | 1.0 Search vendor "Mozilla" for product "Seamonkey" and version "1.0" | beta |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Thunderbird Search vendor "Mozilla" for product "Thunderbird" | 1.0 Search vendor "Mozilla" for product "Thunderbird" and version "1.0" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Thunderbird Search vendor "Mozilla" for product "Thunderbird" | 1.0.1 Search vendor "Mozilla" for product "Thunderbird" and version "1.0.1" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Thunderbird Search vendor "Mozilla" for product "Thunderbird" | 1.0.2 Search vendor "Mozilla" for product "Thunderbird" and version "1.0.2" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Thunderbird Search vendor "Mozilla" for product "Thunderbird" | 1.0.3 Search vendor "Mozilla" for product "Thunderbird" and version "1.0.3" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Thunderbird Search vendor "Mozilla" for product "Thunderbird" | 1.0.4 Search vendor "Mozilla" for product "Thunderbird" and version "1.0.4" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Thunderbird Search vendor "Mozilla" for product "Thunderbird" | 1.0.5 Search vendor "Mozilla" for product "Thunderbird" and version "1.0.5" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Thunderbird Search vendor "Mozilla" for product "Thunderbird" | 1.0.5 Search vendor "Mozilla" for product "Thunderbird" and version "1.0.5" | beta |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Thunderbird Search vendor "Mozilla" for product "Thunderbird" | 1.0.6 Search vendor "Mozilla" for product "Thunderbird" and version "1.0.6" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Thunderbird Search vendor "Mozilla" for product "Thunderbird" | 1.0.7 Search vendor "Mozilla" for product "Thunderbird" and version "1.0.7" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Thunderbird Search vendor "Mozilla" for product "Thunderbird" | 1.5 Search vendor "Mozilla" for product "Thunderbird" and version "1.5" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Thunderbird Search vendor "Mozilla" for product "Thunderbird" | 1.5 Search vendor "Mozilla" for product "Thunderbird" and version "1.5" | beta2 |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Thunderbird Search vendor "Mozilla" for product "Thunderbird" | 1.5.0.1 Search vendor "Mozilla" for product "Thunderbird" and version "1.5.0.1" | - |
Affected
|