Executive Summary
| Informations | |||
|---|---|---|---|
| Name | CVE-2006-3806 | First vendor Publication | 2006-07-27 |
| Vendor | Cve | Last vendor Modification | 2011-09-08 |
Security-Database Scoring CVSS v2
| Cvss vector : (AV:N/AC:L/Au:N/C:P/I:P/A:P) | |||
|---|---|---|---|
| Cvss Base Score | 7.5 | Attack Range | Network |
| Cvss Impact Score | 6.4 | Attack Complexity | Low |
| Cvss Expoit Score | 10 | Authentification | None Required |
| Calculate full CVSS 2.0 Vectors scores | |||
Security Protection
| Impacts | Provides user account access : Allows partial confidentiality, integrity, and availability violation; Allows unauthorized disclosure of information; Allows disruption of service. |
Detail
Multiple integer overflows in the Javascript engine in Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 might allow remote attackers to execute arbitrary code via vectors involving (1) long strings in the toSource method of the Object, Array, and String objects; and (2) unspecified "string function arguments." |
Original Source
| Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3806 |
CWE : Common Weakness Enumeration
| id | Name |
|---|---|
| CWE-189 | Numeric Errors |
OVAL Definitions
CPE : Common Platform Enumeration
| Type | Description | Count |
|---|---|---|
| Application | 5 | |
| Application | 4 | |
| Application | 3 |
Open Source Vulnerability Database (OSVDB)
| id | Description |
|---|---|
| 27571 | Mozilla Multiple Products String Function Objects Unspecified Overflow |
| 27570 | Mozilla Multiple Products toSource Method Overflow |
Internal Sources (Detail)
Alert History
| Date | Informations |
|---|---|
| 2013-05-11 11:04:23 |
|

CVE-2006-3806
(Critical)
(High)






