7.5
CVSSv2

CVE-2006-2788

Published: 02/06/2006 Updated: 03/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Double free vulnerability in the getRawDER function for nsIX509Cert in Firefox allows remote malicious users to cause a denial of service (hang) and possibly execute arbitrary code via certain Javascript code.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox 0.10.1

mozilla firefox 0.8

mozilla firefox 1.0.1

mozilla firefox 1.0.2

mozilla firefox 1.5

mozilla firefox 1.5.0.1

mozilla firefox 0.10

mozilla firefox 0.9

mozilla firefox 1.0

mozilla firefox 1.0.6

mozilla firefox 1.0.7

mozilla firefox 0.9.2

mozilla firefox 0.9.3

mozilla firefox 1.0.5

mozilla firefox preview_release

mozilla firefox 0.9.1

mozilla firefox 1.0.3

mozilla firefox 1.0.4

mozilla firefox 1.5.0.2

mozilla firefox 1.5.0.3

Vendor Advisories

Jonas Sicking discovered that under some circumstances persisted XUL attributes are associated with the wrong URL A malicious web site could exploit this to execute arbitrary code with the privileges of the user (MFSA 2006-35, CVE-2006-2775) ...
USN-296-1 fixed several vulnerabilities in Firefox for the Ubuntu 606 LTS release This update provides the corresponding fixes for Ubuntu 504 and Ubuntu 510 ...
Various flaws have been reported that allow an attacker to execute arbitrary code with user privileges by tricking the user into opening a malicious URL (CVE-2006-2788, CVE-2006-3805, CVE-2006-3806, CVE-2006-3807, CVE-2006-3809, CVE-2006-3811, CVE-2006-4565, CVE-2006-4568, CVE-2006-4571) ...
Several security related problems have been discovered in Mozilla and derived products such as Mozilla Firefox The Common Vulnerabilities and Exposures project identifies the following vulnerabilities: CVE-2006-2788 Fernando Ribeiro discovered that a vulnerability in the getRawDER function allows remote attackers to cause a denial of serv ...
Several security related problems have been discovered in Mozilla and derived products such as Mozilla Thunderbird The Common Vulnerabilities and Exposures project identifies the following vulnerabilities: CVE-2006-2788 Fernando Ribeiro discovered that a vulnerability in the getRawDER function allows remote attackers to cause a denial of ...