VDB

DEBIAN-CVE-2006-2778

DEBIAN-CVE-2006-2778 PUBLISHED CVSS 9.300000190734863 CRITICAL

The crypto.signText function in Mozilla Firefox and Thunderbird before 1.5.0.4 allows remote attackers to execute arbitrary code via certain optional Certificate Authority name arguments, which causes an invalid array index and triggers a buffer overflow.

Risk Scores

CVSS 4.0
9.300000190734863
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected Products

VendorProductVersions
Debian:12thunderbird0, 0, 0
Debian:14thunderbird0, 0, 0
Debian:11thunderbird0, 0, 0
Debian:13thunderbird0, 0, 0

Timeline

  • Jun 2, 2006 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›