CVE Vulnerabilities

CVE-2006-3804

Published: Jul 27, 2006 | Modified: Oct 17, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu

Heap-based buffer overflow in Mozilla Thunderbird before 1.5.0.5 and SeaMonkey before 1.0.3 allows remote attackers to cause a denial of service (crash) via a VCard attachment with a malformed base64 field, which copies more data than expected due to an integer underflow.

Affected Software

Name Vendor Start Version End Version
Seamonkey Mozilla 1.0.1 1.0.1
Seamonkey Mozilla 1.0 1.0
Seamonkey Mozilla 1.0.2 1.0.2
Thunderbird Mozilla 1.5 1.5
Thunderbird Mozilla 1.5.0.2 1.5.0.2
Seamonkey Mozilla 1.0 1.0
Thunderbird Mozilla 1.5.0.4 1.5.0.4

References