{"cves":[{"id":"CVE-2006-2878","published":"2006-06-07T00:02:00","updated_at":"2025-07-17T16:38:59.754056+00:00","description":"\nThe spellchecker (spellcheck.php) in DokuWiki 2006/06/04 and earlier allows\nremote attackers to insert and execute arbitrary PHP code via \"complex\ncurly syntax\" that is inserted into a regular expression that is processed\nby preg_replace with the /e (executable) modifier.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-2878"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"dokuwiki","source":"https://ubuntu.com/security/cve?package=dokuwiki","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=dokuwiki","debian":"https://tracker.debian.org/pkg/dokuwiki","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"0.0.20060309-4","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"0.0.20060309-4","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"0.0.20060309-4","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"0.0.20060309-4","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"0.0.20060309-4","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"0.0.20060309-4","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"0.0.20060309-4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"20060605","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-2447","published":"2006-06-06T21:06:00","updated_at":"2025-07-17T16:38:46.188028+00:00","description":"\nSpamAssassin before 3.1.3, when running with vpopmail and the paranoid (-P)\nswitch, allows remote attackers to execute arbitrary commands via a crafted\nmessage that is not properly handled when invoking spamd with the virtual\npop username.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-2447"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"spamassassin","source":"https://ubuntu.com/security/cve?package=spamassassin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=spamassassin","debian":"https://tracker.debian.org/pkg/spamassassin","statuses":[{"release_codename":"dapper","status":"released","description":"3.1.0a-2ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"3.1.4-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"3.1.4-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-2842","published":"2006-06-06T20:06:00","updated_at":"2025-08-04T19:18:39.145764+00:00","description":"\nPHP remote file inclusion vulnerability in functions/plugin.php in\nSquirrelMail 1.4.6 and earlier, if register_globals is enabled and\nmagic_quotes_gpc is disabled, allows remote attackers to execute arbitrary\nPHP code via a URL in the plugins array parameter. NOTE: this issue has\nbeen disputed by third parties, who state that Squirrelmail provides\nprominent warnings to the administrator when register_globals is enabled.\nSince the varieties of administrator negligence are uncountable, perhaps\nthis type of issue should not be included in CVE. However, the original\ndeveloper has posted a security advisory, so there might be relevant\nreal-world environments under which this vulnerability is applicable","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-2842"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"squirrelmail","source":"https://ubuntu.com/security/cve?package=squirrelmail","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=squirrelmail","debian":"https://tracker.debian.org/pkg/squirrelmail","statuses":[{"release_codename":"dapper","status":"released","description":"1.4.6-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.4.8-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.4.9a-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-2833","published":"2006-06-06T00:02:00","updated_at":"2025-07-17T16:38:59.754056+00:00","description":"\nCross-site scripting (XSS) vulnerability in the taxonomy module in Drupal\n4.6.8 and 4.7.2 allows remote attackers to inject arbitrary web script or\nHTML via inputs that are not properly validated when the page title is\noutput, possibly involving the $names variable.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-2833"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"drupal","source":"https://ubuntu.com/security/cve?package=drupal","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=drupal","debian":"https://tracker.debian.org/pkg/drupal","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"4.5.8-2","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-2832","published":"2006-06-06T00:02:00","updated_at":"2025-07-17T16:38:59.754056+00:00","description":"\nCross-site scripting (XSS) vulnerability in the upload module\n(upload.module) in Drupal 4.6.x before 4.6.8 and 4.7.x before 4.7.2 allows\nremote attackers to inject arbitrary web script or HTML via the uploaded\nfilename.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-2832"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"drupal","source":"https://ubuntu.com/security/cve?package=drupal","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=drupal","debian":"https://tracker.debian.org/pkg/drupal","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"4.5.8-2","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-2831","published":"2006-06-06T00:02:00","updated_at":"2025-07-17T16:38:59.754056+00:00","description":"\nDrupal 4.6.x before 4.6.8 and 4.7.x before 4.7.2, when running under\ncertain Apache configurations such as when FileInfo overrides are disabled\nwithin .htaccess, allows remote attackers to execute arbitrary code by\nuploading a file with multiple extensions, a variant of CVE-2006-2743.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-2831"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"drupal","source":"https://ubuntu.com/security/cve?package=drupal","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=drupal","debian":"https://tracker.debian.org/pkg/drupal","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-2825","published":"2006-06-05T17:02:00","updated_at":"2025-07-17T16:38:59.754056+00:00","description":"\ncPanel does not automatically synchronize the PHP open_basedir\nconfiguration directive between the main server and virtual hosts that\nshare physical directories, which might allow a local user to bypass\nopen_basedir restrictions and access other virtual hosts via a PHP script\nthat uses a main server URL (such as ~username) that is blocked by the\nuser's own open_basedir directive, but not the main server's open_basedir\ndirective.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-2825"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"cpanel","source":"https://ubuntu.com/security/cve?package=cpanel","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=cpanel","debian":"https://tracker.debian.org/pkg/cpanel","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-2802","published":"2006-06-03T00:00:00","updated_at":"2025-07-17T16:38:59.754056+00:00","description":"\nBuffer overflow in the HTTP Plugin (xineplug_inp_http.so) for xine-lib\n1.1.1 allows remote attackers to cause a denial of service (application\ncrash) via a long reply from an HTTP server, as demonstrated using gxine\n0.5.6.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-295-1","https://www.cve.org/CVERecord?id=CVE-2006-2802"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"xine-extracodecs","source":"https://ubuntu.com/security/cve?package=xine-extracodecs","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xine-extracodecs","debian":"https://tracker.debian.org/pkg/xine-extracodecs","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.1.2-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.1.2-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"xine-lib","source":"https://ubuntu.com/security/cve?package=xine-lib","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xine-lib","debian":"https://tracker.debian.org/pkg/xine-lib","statuses":[{"release_codename":"dapper","status":"released","description":"1.1.1+ubuntu2-7.7","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.1.2+repacked1-0ubuntu3.4","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.1.4-2ubuntu3","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"released","description":"1.1.4-2ubuntu3","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.1.4-2ubuntu3","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.1.4-2ubuntu3","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.1.4-2ubuntu3","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1.1.4-2ubuntu3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-295-1"],"notices":[{"id":"USN-295-1","title":"xine-lib vulnerability","summary":"xine-lib vulnerability","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.\nXXX OR XXX\nAfter a standard system upgrade you need to reboot your computer to\neffect the necessary changes.","references":[],"published":"2006-06-09T19:46:43","description":"Federico L. Bossi Bonin discovered a buffer overflow in the HTTP input\nmodule. By tricking an user into opening a malicious remote media\nlocation, a remote attacker could exploit this to crash Xine library\nfrontends (like totem-xine, gxine, or xine-ui) and possibly even\nexecute arbitrary code with the user's privileges.","is_hidden":false,"release_packages":{"dapper":[{"name":"libxine-main1","version":"1.1.1+ubuntu2-7.1","is_source":false,"source_link":"","version_link":""}],"hoary":[{"name":"libxine1","version":"1.0-1ubuntu3.7","is_source":false,"source_link":"","version_link":""}],"breezy":[{"name":"libxine1c2","version":"1.0.1-1ubuntu10.3","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2006-2802"]}]},{"id":"CVE-2006-2789","published":"2006-06-02T22:02:00","updated_at":"2025-07-17T16:38:57.863203+00:00","description":"\nEvolution 2.2.x and 2.3.x in GNOME 2.7 and 2.8, when \"load images if sender\nin addressbook\" is enabled, allows remote attackers to cause a denial of\nservice (persistent crash) via a crafted \"From\" header that triggers an\nassert error in camel-internet-address.c when a null pointer is used.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2006-2789"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"evolution","source":"https://ubuntu.com/security/cve?package=evolution","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=evolution","debian":"https://tracker.debian.org/pkg/evolution","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-2788","published":"2006-06-02T21:06:00","updated_at":"2025-07-17T16:38:57.863203+00:00","description":"\nDouble free vulnerability in the getRawDER function for nsIX509Cert in\nFirefox allows remote attackers to cause a denial of service (hang) and\npossibly execute arbitrary code via certain Javascript code.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-296-1","https://ubuntu.com/security/notices/USN-361-1","https://www.cve.org/CVERecord?id=CVE-2006-2788"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"dapper","status":"released","description":"1.5.dfsg+1.5.0.13~prepatch070731-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"firefox-granparadiso","source":"https://ubuntu.com/security/cve?package=firefox-granparadiso","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox-granparadiso","debian":"https://tracker.debian.org/pkg/firefox-granparadiso","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"lightning-sunbird","source":"https://ubuntu.com/security/cve?package=lightning-sunbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=lightning-sunbird","debian":"https://tracker.debian.org/pkg/lightning-sunbird","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"midbrowser","source":"https://ubuntu.com/security/cve?package=midbrowser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=midbrowser","debian":"https://tracker.debian.org/pkg/midbrowser","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-361-1","USN-296-1"],"notices":[{"id":"USN-361-1","title":"Mozilla vulnerabilities","summary":"Mozilla vulnerabilities","instructions":"After a standard system upgrade you need to restart Mozilla to effect\nthe necessary changes.","references":[],"published":"2006-10-10T23:15:50","description":"Various flaws have been reported that allow an attacker to execute\narbitrary code with user privileges by tricking the user into opening\na malicious URL. (CVE-2006-2788, CVE-2006-3805, CVE-2006-3806,\nCVE-2006-3807, CVE-2006-3809, CVE-2006-3811, CVE-2006-4565,\nCVE-2006-4568, CVE-2006-4571)\n\nA bug was found in the script handler for automatic proxy\nconfiguration. A malicious proxy could send scripts which could\nexecute arbitrary code with the user's privileges. (CVE-2006-3808)\n\nThe NSS library did not sufficiently check the padding of PKCS #1 v1.5\nsignatures if the exponent of the public key is 3 (which is widely\nused for CAs). This could be exploited to forge valid signatures\nwithout the need of the secret key. (CVE-2006-4340)\n\nGeorgi Guninski discovered that even with JavaScript disabled, a\nmalicous email could still execute JavaScript when the message is\nviewed, replied to, or forwarded by putting the script in a remote XBL\nfile loaded by the message. (CVE-2006-4570)","is_hidden":false,"release_packages":{"hoary":[{"name":"mozilla-psm","version":"2:1.7.13-0ubuntu05.04.2","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-mailnews","version":"2:1.7.13-0ubuntu05.04.2","is_source":false,"source_link":"","version_link":""},{"name":"libnspr4","version":"2:1.7.13-0ubuntu05.04.2","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-browser","version":"2:1.7.13-0ubuntu05.04.2","is_source":false,"source_link":"","version_link":""},{"name":"libnss3","version":"2:1.7.13-0ubuntu05.04.2","is_source":false,"source_link":"","version_link":""}],"breezy":[{"name":"mozilla-psm","version":"2:1.7.13-0ubuntu5.10.2","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-mailnews","version":"2:1.7.13-0ubuntu5.10.2","is_source":false,"source_link":"","version_link":""},{"name":"libnspr4","version":"2:1.7.13-0ubuntu5.10.2","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-browser","version":"2:1.7.13-0ubuntu5.10.2","is_source":false,"source_link":"","version_link":""},{"name":"libnss3","version":"2:1.7.13-0ubuntu5.10.2","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2006-2788","CVE-2006-3805","CVE-2006-3806","CVE-2006-3807","CVE-2006-3808","CVE-2006-3809","CVE-2006-3811","CVE-2006-4340","CVE-2006-4565","CVE-2006-4568","CVE-2006-4570","CVE-2006-4571"]},{"id":"USN-296-1","title":"firefox vulnerabilities","summary":"firefox vulnerabilities","instructions":"After a standard system upgrade you need to restart Firefox to effect\nthe necessary changes.\n\nPlease note that Firefox 1.0.8 in Ubuntu 5.10 and Ubuntu 5.04 are also\naffected by these problems. Updates for these Ubuntu releases will be\ndelayed due to upstream dropping support for this Firefox version. We\nstrongly advise that you disable JavaScript to disable the attack\nvectors for most vulnerabilities if you use one of these Ubuntu\nversions.","references":[],"published":"2006-06-09T22:13:38","description":"Jonas Sicking discovered that under some circumstances persisted XUL\nattributes are associated with the wrong URL. A malicious web site\ncould exploit this to execute arbitrary code with the privileges of\nthe user. (MFSA 2006-35, CVE-2006-2775)\n\nPaul Nickerson discovered that content-defined setters on an object\nprototype were getting called by privileged UI code. It was\ndemonstrated that this could be exploited to run arbitrary web script\nwith full user privileges (MFSA 2006-37, CVE-2006-2776). A similar\nattack was discovered by moz_bug_r_a4 that leveraged SelectionObject\nnotifications that were called in privileged context. (MFSA 2006-43,\nCVE-2006-2777)\n\nMikolaj Habryn discovered a buffer overflow in the crypto.signText()\nfunction. By tricking a user to visit a site with an SSL certificate\nwith specially crafted optional Certificate Authority name\narguments, this could potentially be exploited to execute arbitrary\ncode with the user's privileges. (MFSA 2006-38, CVE-2006-2778)\n\nThe Mozilla developer team discovered several bugs that lead to\ncrashes with memory corruption. These might be exploitable by\nmalicious web sites to execute arbitrary code with the privileges of\nthe user. (MFSA 2006-32, CVE-2006-2779, CVE-2006-2780, CVE-2006-2788)\n\nChuck McAuley reported that the fix for CVE-2006-1729 (file stealing\nby changing input type) was not sufficient to prevent all variants of\nexploitation. (MFSA 2006-41, CVE-2006-2782)\n\nMasatoshi Kimura found a way to bypass web input sanitizers which\nfilter out JavaScript. By inserting 'Unicode Byte-order-Mark (BOM)'\ncharacters into the HTML code (e. g. ''), these filters\nmight not recognize the tags anymore; however, Firefox would still\nexecute them since BOM markers are filtered out before processing the\npage. (MFSA 2006-42, CVE-2006-2783)\n\nPaul Nickerson noticed that the fix for CVE-2005-0752 (JavaScript\nprivilege escalation on the plugins page) was not sufficient to\nprevent all variants of exploitation. (MFSA 2006-36, CVE-2006-2784)\n\nPaul Nickerson demonstrated that if an attacker could convince a user\nto right-click on a broken image and choose \"View Image\" from the\ncontext menu then he could get JavaScript to run on a site of the\nattacker's choosing. This could be used to steal login cookies or\nother confidential information from the target site. (MFSA 2006-34,\nCVE-2006-2785)\n\nKazuho Oku discovered various ways to perform HTTP response smuggling\nwhen used with certain proxy servers. Due to different interpretation\nof nonstandard HTTP headers in Firefox and the proxy server, a\nmalicious web site can exploit this to send back two responses to one\nrequest. The second response could be used to steal login cookies or\nother sensitive data from another opened web site. (MFSA 2006-33,\nCVE-2006-2786)","is_hidden":false,"release_packages":{"dapper":[{"name":"firefox","version":"1.5.dfsg+1.5.0.4-0ubuntu6.06","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2006-2775","CVE-2006-2776","CVE-2006-2777","CVE-2006-2778","CVE-2006-2779","CVE-2006-2780","CVE-2006-2782","CVE-2006-2783","CVE-2006-2784","CVE-2006-2785","CVE-2006-2786","CVE-2006-2787","CVE-2006-2788"]}]},{"id":"CVE-2006-2787","published":"2006-06-02T20:02:00","updated_at":"2025-07-17T16:38:57.863203+00:00","description":"\nEvalInSandbox in Mozilla Firefox and Thunderbird before 1.5.0.4 allows\nremote attackers to gain privileges via javascript that calls the valueOf\nmethod on objects that were created outside of the sandbox.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-296-1","https://ubuntu.com/security/notices/USN-296-2","https://ubuntu.com/security/notices/USN-297-1","https://ubuntu.com/security/notices/USN-297-3","https://ubuntu.com/security/notices/USN-323-1","https://www.cve.org/CVERecord?id=CVE-2006-2787"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"dapper","status":"released","description":"1.5.dfsg+1.5.0.13~prepatch070731-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"firefox-granparadiso","source":"https://ubuntu.com/security/cve?package=firefox-granparadiso","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox-granparadiso","debian":"https://tracker.debian.org/pkg/firefox-granparadiso","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"lightning-sunbird","source":"https://ubuntu.com/security/cve?package=lightning-sunbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=lightning-sunbird","debian":"https://tracker.debian.org/pkg/lightning-sunbird","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"midbrowser","source":"https://ubuntu.com/security/cve?package=midbrowser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=midbrowser","debian":"https://tracker.debian.org/pkg/midbrowser","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mozilla-thunderbird","source":"https://ubuntu.com/security/cve?package=mozilla-thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozilla-thunderbird","debian":"https://tracker.debian.org/pkg/mozilla-thunderbird","statuses":[{"release_codename":"dapper","status":"released","description":"1.5.0.13-0ubuntu0.6.06","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.5.0.13-0ubuntu0.6.10","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.5.0.13-0ubuntu0.7.04","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"xulrunner","source":"https://ubuntu.com/security/cve?package=xulrunner","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xulrunner","debian":"https://tracker.debian.org/pkg/xulrunner","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.8.0.5-4.2","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.8.0.5-4.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-323-1","USN-297-1","USN-297-3","USN-296-2","USN-296-1"],"notices":[{"id":"USN-323-1","title":"mozilla vulnerabilities","summary":"mozilla vulnerabilities","instructions":"After a standard system upgrade you need to restart Mozilla to effect\nthe necessary changes.","references":[],"published":"2006-07-26T02:47:37","description":"Jonas Sicking discovered that under some circumstances persisted XUL\nattributes are associated with the wrong URL. A malicious web site\ncould exploit this to execute arbitrary code with the privileges of\nthe user. (MFSA 2006-35, CVE-2006-2775)\n\nPaul Nickerson discovered that content-defined setters on an object\nprototype were getting called by privileged UI code. It was\ndemonstrated that this could be exploited to run arbitrary web script\nwith full user privileges (MFSA 2006-37, CVE-2006-2776). A similar\nattack was discovered by moz_bug_r_a4 that leveraged SelectionObject\nnotifications that were called in privileged context. (MFSA 2006-43,\nCVE-2006-2777)\n\nMikolaj Habryn discovered a buffer overflow in the crypto.signText()\nfunction. By tricking a user to visit a site with an SSL certificate\nwith specially crafted optional Certificate Authority name\narguments, this could potentially be exploited to execute arbitrary\ncode with the user's privileges. (MFSA 2006-38, CVE-2006-2778)\n\nThe Mozilla developer team discovered several bugs that lead to\ncrashes with memory corruption. These might be exploitable by\nmalicious web sites to execute arbitrary code with the privileges of\nthe user. (MFSA 2006-32, CVE-2006-2779, CVE-2006-2780)\n\nMasatoshi Kimura discovered a memory corruption (double-free) when\nprocessing a large VCard with invalid base64 characters in it. By\nsending a maliciously crafted set of VCards to a user, this could\npotentially be exploited to execute arbitrary code with the user's\nprivileges. (MFSA 2006-40, CVE-2006-2781)\n\nChuck McAuley reported that the fix for CVE-2006-1729 (file stealing\nby changing input type) was not sufficient to prevent all variants of\nexploitation. (MFSA 2006-41, CVE-2006-2782)\n\nMasatoshi Kimura found a way to bypass web input sanitizers which\nfilter out JavaScript. By inserting 'Unicode Byte-order-Mark (BOM)'\ncharacters into the HTML code (e. g. ''), these filters\nmight not recognize the tags anymore; however, Mozilla would still\nexecute them since BOM markers are filtered out before processing the\npage. (MFSA 2006-42, CVE-2006-2783)\n\nPaul Nickerson noticed that the fix for CVE-2005-0752 (JavaScript\nprivilege escalation on the plugins page) was not sufficient to\nprevent all variants of exploitation. (MFSA 2006-36, CVE-2006-2784)\n\nPaul Nickerson demonstrated that if an attacker could convince a user\nto right-click on a broken image and choose \"View Image\" from the\ncontext menu then he could get JavaScript to run on a site of the\nattacker's choosing. This could be used to steal login cookies or\nother confidential information from the target site. (MFSA 2006-34,\nCVE-2006-2785)\n\nKazuho Oku discovered various ways to perform HTTP response smuggling\nwhen used with certain proxy servers. Due to different interpretation\nof nonstandard HTTP headers in Mozilla and the proxy server, a\nmalicious web site can exploit this to send back two responses to one\nrequest. The second response could be used to steal login cookies or\nother sensitive data from another opened web site. (MFSA 2006-33,\nCVE-2006-2786)","is_hidden":false,"release_packages":{"hoary":[{"name":"mozilla-psm","version":"2:1.7.13-0ubuntu05.04.1","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-mailnews","version":"2:1.7.13-0ubuntu05.04.1","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-browser","version":"2:1.7.13-0ubuntu05.04.1","is_source":false,"source_link":"","version_link":""}],"breezy":[{"name":"mozilla-psm","version":"2:1.7.13-0ubuntu5.10.1","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-mailnews","version":"2:1.7.13-0ubuntu5.10.1","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-browser","version":"2:1.7.13-0ubuntu5.10.1","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2006-2775","CVE-2006-2776","CVE-2006-2777","CVE-2006-2778","CVE-2006-2779","CVE-2006-2780","CVE-2006-2781","CVE-2006-2782","CVE-2006-2783","CVE-2006-2784","CVE-2006-2785","CVE-2006-2786","CVE-2006-2787"]},{"id":"USN-297-1","title":"Thunderbird vulnerabilities","summary":"Thunderbird vulnerabilities","instructions":"After a standard system upgrade you need to restart Thunderbird to\neffect the necessary changes.\n\nPlease note that Thunderbird 1.0.8 in Ubuntu 5.10 and Ubuntu 5.04 are\nalso affected by these problems. Updates for these Ubuntu releases\nwill be delayed due to upstream dropping support for this Thunderbird\nversion. We strongly advise that you disable JavaScript to disable the\nattack vectors for most vulnerabilities if you use one of these Ubuntu\nversions.","references":[],"published":"2006-06-14T17:45:48","description":"Jonas Sicking discovered that under some circumstances persisted XUL\nattributes are associated with the wrong URL. A malicious web site\ncould exploit this to execute arbitrary code with the privileges of\nthe user. (MFSA 2006-35, CVE-2006-2775)\n\nPaul Nickerson discovered that content-defined setters on an object\nprototype were getting called by privileged UI code. It was\ndemonstrated that this could be exploited to run arbitrary web script\nwith full user privileges (MFSA 2006-37, CVE-2006-2776).\n\nMikolaj Habryn discovered a buffer overflow in the crypto.signText()\nfunction. By sending an email with malicious JavaScript to an user,\nand that user enabled JavaScript in Thunderbird (which is not the\ndefault and not recommended), this could potentially be exploited to\nexecute arbitrary code with the user's privileges. (MFSA 2006-38,\nCVE-2006-2778)\n\nThe Mozilla developer team discovered several bugs that lead to\ncrashes with memory corruption. These might be exploitable by\nmalicious web sites to execute arbitrary code with the privileges of\nthe user. (MFSA 2006-32, CVE-2006-2779, CVE-2006-2780)\n\nMasatoshi Kimura discovered a memory corruption (double-free) when\nprocessing a large VCard with invalid base64 characters in it. By\nsending a maliciously crafted set of VCards to a user, this could\npotentially be exploited to execute arbitrary code with the user's\nprivileges. (MFSA 2006-40, CVE-2006-2781)\n\nMasatoshi Kimura found a way to bypass web input sanitizers which\nfilter out JavaScript. By inserting 'Unicode Byte-order-Mark (BOM)'\ncharacters into the HTML code (e. g. ''), these filters\nmight not recognize the tags anymore; however, Thunderbird would still\nexecute them since BOM markers are filtered out before processing a\nmail containing JavaScript. (MFSA 2006-42, CVE-2006-2783)\n\nKazuho Oku discovered various ways to perform HTTP response smuggling\nwhen used with certain proxy servers. Due to different interpretation\nof nonstandard HTTP headers in Thunderbird and the proxy server, a\nmalicious HTML email can exploit this to send back two responses to one\nrequest. The second response could be used to steal login cookies or\nother sensitive data from another opened web site. (MFSA 2006-33,\nCVE-2006-2786)\n\nIt was discovered that JavaScript run via EvalInSandbox() can escape\nthe sandbox. Malicious scripts received in emails containing\nJavaScript could use these privileges to execute arbitrary code with\nthe user's privileges. (MFSA 2006-31, CVE-2006-2787)\n\nThe \"enigmail\" plugin has been updated to work with the new\nThunderbird version.","is_hidden":false,"release_packages":{"dapper":[{"name":"mozilla-thunderbird","version":"1.5.0.4-0ubuntu6.06","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-thunderbird-enigmail","version":"2:0.94-0ubuntu4.1","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2006-2775","CVE-2006-2776","CVE-2006-2778","CVE-2006-2779","CVE-2006-2780","CVE-2006-2781","CVE-2006-2783","CVE-2006-2786","CVE-2006-2787"]},{"id":"USN-297-3","title":"Thunderbird vulnerabilities","summary":"Thunderbird vulnerabilities","instructions":"After a standard system upgrade you need to restart Thunderbird to\neffect the necessary changes.","references":[],"published":"2006-07-26T17:25:23","description":"USN-297-1 fixed several vulnerabilities in Thunderbird for the Ubuntu\n6.06 LTS release. This update provides the corresponding fixes for\nUbuntu 5.04 and Ubuntu 5.10.\n\nFor reference, these are the details of the original USN:\n\n Jonas Sicking discovered that under some circumstances persisted XUL\n attributes are associated with the wrong URL. A malicious web site\n could exploit this to execute arbitrary code with the privileges of\n the user. (MFSA 2006-35, CVE-2006-2775)\n\n Paul Nickerson discovered that content-defined setters on an object\n prototype were getting called by privileged UI code. It was\n demonstrated that this could be exploited to run arbitrary web\n script with full user privileges (MFSA 2006-37, CVE-2006-2776).\n\n Mikolaj Habryn discovered a buffer overflow in the crypto.signText()\n function. By sending an email with malicious JavaScript to an user,\n and that user enabled JavaScript in Thunderbird (which is not the\n default and not recommended), this could potentially be exploited to\n execute arbitrary code with the user's privileges. (MFSA 2006-38,\n CVE-2006-2778)\n\n The Mozilla developer team discovered several bugs that lead to\n crashes with memory corruption. These might be exploitable by\n malicious web sites to execute arbitrary code with the privileges of\n the user. (MFSA 2006-32, CVE-2006-2779, CVE-2006-2780)\n\n Masatoshi Kimura discovered a memory corruption (double-free) when\n processing a large VCard with invalid base64 characters in it. By\n sending a maliciously crafted set of VCards to a user, this could\n potentially be exploited to execute arbitrary code with the user's\n privileges. (MFSA 2006-40, CVE-2006-2781)\n\n Masatoshi Kimura found a way to bypass web input sanitizers which\n filter out JavaScript. By inserting 'Unicode Byte-order-Mark (BOM)'\n characters into the HTML code (e. g. ''), these filters\n might not recognize the tags anymore; however, Thunderbird would\n still execute them since BOM markers are filtered out before\n processing a mail containing JavaScript. (MFSA 2006-42,\n CVE-2006-2783)\n\n Kazuho Oku discovered various ways to perform HTTP response\n smuggling when used with certain proxy servers. Due to different\n interpretation of nonstandard HTTP headers in Thunderbird and the\n proxy server, a malicious HTML email can exploit this to send back\n two responses to one request. The second response could be used to\n steal login cookies or other sensitive data from another opened web\n site. (MFSA 2006-33, CVE-2006-2786)\n\n It was discovered that JavaScript run via EvalInSandbox() can escape\n the sandbox. Malicious scripts received in emails containing\n JavaScript could use these privileges to execute arbitrary code with\n the user's privileges. (MFSA 2006-31, CVE-2006-2787)","is_hidden":false,"release_packages":{"hoary":[{"name":"mozilla-thunderbird","version":"1.0.8-0ubuntu05.04.1","is_source":false,"source_link":"","version_link":""}],"breezy":[{"name":"mozilla-thunderbird","version":"1.0.8-0ubuntu05.10.2","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2006-2775","CVE-2006-2776","CVE-2006-2778","CVE-2006-2779","CVE-2006-2780","CVE-2006-2781","CVE-2006-2783","CVE-2006-2784","CVE-2006-2787"]},{"id":"USN-296-2","title":"Firefox vulnerabilities","summary":"Firefox vulnerabilities","instructions":"After a standard system upgrade you need to restart Firefox to effect\nthe necessary changes.","references":[],"published":"2006-07-25T17:49:50","description":"USN-296-1 fixed several vulnerabilities in Firefox for the Ubuntu 6.06\nLTS release. This update provides the corresponding fixes for Ubuntu\n5.04 and Ubuntu 5.10.\n\nFor reference, these are the details of the original USN:\n\n Jonas Sicking discovered that under some circumstances persisted XUL\n attributes are associated with the wrong URL. A malicious web site\n could exploit this to execute arbitrary code with the privileges of\n the user. (MFSA 2006-35, CVE-2006-2775)\n \n Paul Nickerson discovered that content-defined setters on an object\n prototype were getting called by privileged UI code. It was\n demonstrated that this could be exploited to run arbitrary web script\n with full user privileges (MFSA 2006-37, CVE-2006-2776). A similar\n attack was discovered by moz_bug_r_a4 that leveraged SelectionObject\n notifications that were called in privileged context. (MFSA 2006-43,\n CVE-2006-2777)\n \n Mikolaj Habryn discovered a buffer overflow in the crypto.signText()\n function. By tricking a user to visit a site with an SSL certificate\n with specially crafted optional Certificate Authority name\n arguments, this could potentially be exploited to execute arbitrary\n code with the user's privileges. (MFSA 2006-38, CVE-2006-2778)\n \n The Mozilla developer team discovered several bugs that lead to\n crashes with memory corruption. These might be exploitable by\n malicious web sites to execute arbitrary code with the privileges of\n the user. (MFSA 2006-32, CVE-2006-2779, CVE-2006-2780, CVE-2006-2788)\n \n Chuck McAuley reported that the fix for CVE-2006-1729 (file stealing\n by changing input type) was not sufficient to prevent all variants of\n exploitation. (MFSA 2006-41, CVE-2006-2782)\n \n Masatoshi Kimura found a way to bypass web input sanitizers which\n filter out JavaScript. By inserting 'Unicode Byte-order-Mark (BOM)'\n characters into the HTML code (e. g. ''), these filters\n might not recognize the tags anymore; however, Firefox would still\n execute them since BOM markers are filtered out before processing the\n page. (MFSA 2006-42, CVE-2006-2783)\n \n Paul Nickerson noticed that the fix for CVE-2005-0752 (JavaScript\n privilege escalation on the plugins page) was not sufficient to\n prevent all variants of exploitation. (MFSA 2006-36, CVE-2006-2784)\n \n Paul Nickerson demonstrated that if an attacker could convince a user\n to right-click on a broken image and choose \"View Image\" from the\n context menu then he could get JavaScript to run on a site of the\n attacker's choosing. This could be used to steal login cookies or\n other confidential information from the target site. (MFSA 2006-34,\n CVE-2006-2785)\n \n Kazuho Oku discovered various ways to perform HTTP response smuggling\n when used with certain proxy servers. Due to different interpretation\n of nonstandard HTTP headers in Firefox and the proxy server, a\n malicious web site can exploit this to send back two responses to one\n request. The second response could be used to steal login cookies or\n other sensitive data from another opened web site. (MFSA 2006-33,\n CVE-2006-2786)","is_hidden":false,"release_packages":{"hoary":[{"name":"mozilla-firefox","version":"1.0.8-0ubuntu5.04.1","is_source":false,"source_link":"","version_link":""}],"breezy":[{"name":"firefox","version":"1.0.8-0ubuntu5.10.1","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2006-2775","CVE-2006-2776","CVE-2006-2777","CVE-2006-2778","CVE-2006-2779","CVE-2006-2780","CVE-2006-2782","CVE-2006-2783","CVE-2006-2784","CVE-2006-2785","CVE-2006-2786","CVE-2006-2787"]},{"id":"USN-296-1","title":"firefox vulnerabilities","summary":"firefox vulnerabilities","instructions":"After a standard system upgrade you need to restart Firefox to effect\nthe necessary changes.\n\nPlease note that Firefox 1.0.8 in Ubuntu 5.10 and Ubuntu 5.04 are also\naffected by these problems. Updates for these Ubuntu releases will be\ndelayed due to upstream dropping support for this Firefox version. We\nstrongly advise that you disable JavaScript to disable the attack\nvectors for most vulnerabilities if you use one of these Ubuntu\nversions.","references":[],"published":"2006-06-09T22:13:38","description":"Jonas Sicking discovered that under some circumstances persisted XUL\nattributes are associated with the wrong URL. A malicious web site\ncould exploit this to execute arbitrary code with the privileges of\nthe user. (MFSA 2006-35, CVE-2006-2775)\n\nPaul Nickerson discovered that content-defined setters on an object\nprototype were getting called by privileged UI code. It was\ndemonstrated that this could be exploited to run arbitrary web script\nwith full user privileges (MFSA 2006-37, CVE-2006-2776). A similar\nattack was discovered by moz_bug_r_a4 that leveraged SelectionObject\nnotifications that were called in privileged context. (MFSA 2006-43,\nCVE-2006-2777)\n\nMikolaj Habryn discovered a buffer overflow in the crypto.signText()\nfunction. By tricking a user to visit a site with an SSL certificate\nwith specially crafted optional Certificate Authority name\narguments, this could potentially be exploited to execute arbitrary\ncode with the user's privileges. (MFSA 2006-38, CVE-2006-2778)\n\nThe Mozilla developer team discovered several bugs that lead to\ncrashes with memory corruption. These might be exploitable by\nmalicious web sites to execute arbitrary code with the privileges of\nthe user. (MFSA 2006-32, CVE-2006-2779, CVE-2006-2780, CVE-2006-2788)\n\nChuck McAuley reported that the fix for CVE-2006-1729 (file stealing\nby changing input type) was not sufficient to prevent all variants of\nexploitation. (MFSA 2006-41, CVE-2006-2782)\n\nMasatoshi Kimura found a way to bypass web input sanitizers which\nfilter out JavaScript. By inserting 'Unicode Byte-order-Mark (BOM)'\ncharacters into the HTML code (e. g. ''), these filters\nmight not recognize the tags anymore; however, Firefox would still\nexecute them since BOM markers are filtered out before processing the\npage. (MFSA 2006-42, CVE-2006-2783)\n\nPaul Nickerson noticed that the fix for CVE-2005-0752 (JavaScript\nprivilege escalation on the plugins page) was not sufficient to\nprevent all variants of exploitation. (MFSA 2006-36, CVE-2006-2784)\n\nPaul Nickerson demonstrated that if an attacker could convince a user\nto right-click on a broken image and choose \"View Image\" from the\ncontext menu then he could get JavaScript to run on a site of the\nattacker's choosing. This could be used to steal login cookies or\nother confidential information from the target site. (MFSA 2006-34,\nCVE-2006-2785)\n\nKazuho Oku discovered various ways to perform HTTP response smuggling\nwhen used with certain proxy servers. Due to different interpretation\nof nonstandard HTTP headers in Firefox and the proxy server, a\nmalicious web site can exploit this to send back two responses to one\nrequest. The second response could be used to steal login cookies or\nother sensitive data from another opened web site. (MFSA 2006-33,\nCVE-2006-2786)","is_hidden":false,"release_packages":{"dapper":[{"name":"firefox","version":"1.5.dfsg+1.5.0.4-0ubuntu6.06","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2006-2775","CVE-2006-2776","CVE-2006-2777","CVE-2006-2778","CVE-2006-2779","CVE-2006-2780","CVE-2006-2782","CVE-2006-2783","CVE-2006-2784","CVE-2006-2785","CVE-2006-2786","CVE-2006-2787","CVE-2006-2788"]}]},{"id":"CVE-2006-2786","published":"2006-06-02T20:02:00","updated_at":"2025-07-17T16:38:57.863203+00:00","description":"\nHTTP response smuggling vulnerability in Mozilla Firefox and Thunderbird\nbefore 1.5.0.4, when used with certain proxy servers, allows remote\nattackers to cause Firefox to interpret certain responses as if they were\nresponses from two different sites via (1) invalid HTTP response headers\nwith spaces between the header name and the colon, which might not be\nignored in some cases, or (2) HTTP 1.1 headers through an HTTP 1.0 proxy,\nwhich are ignored by the proxy but processed by the client.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-296-1","https://ubuntu.com/security/notices/USN-296-2","https://ubuntu.com/security/notices/USN-297-1","https://ubuntu.com/security/notices/USN-323-1","https://www.cve.org/CVERecord?id=CVE-2006-2786"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"dapper","status":"released","description":"1.5.dfsg+1.5.0.13~prepatch070731-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"firefox-granparadiso","source":"https://ubuntu.com/security/cve?package=firefox-granparadiso","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox-granparadiso","debian":"https://tracker.debian.org/pkg/firefox-granparadiso","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"lightning-sunbird","source":"https://ubuntu.com/security/cve?package=lightning-sunbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=lightning-sunbird","debian":"https://tracker.debian.org/pkg/lightning-sunbird","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"midbrowser","source":"https://ubuntu.com/security/cve?package=midbrowser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=midbrowser","debian":"https://tracker.debian.org/pkg/midbrowser","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mozilla-thunderbird","source":"https://ubuntu.com/security/cve?package=mozilla-thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozilla-thunderbird","debian":"https://tracker.debian.org/pkg/mozilla-thunderbird","statuses":[{"release_codename":"dapper","status":"released","description":"1.5.0.13-0ubuntu0.6.06","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.5.0.13-0ubuntu0.6.10","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.5.0.13-0ubuntu0.7.04","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"xulrunner","source":"https://ubuntu.com/security/cve?package=xulrunner","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xulrunner","debian":"https://tracker.debian.org/pkg/xulrunner","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.8.0.5-4.2","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.8.0.5-4.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-323-1","USN-297-1","USN-296-2","USN-296-1"],"notices":[{"id":"USN-323-1","title":"mozilla vulnerabilities","summary":"mozilla vulnerabilities","instructions":"After a standard system upgrade you need to restart Mozilla to effect\nthe necessary changes.","references":[],"published":"2006-07-26T02:47:37","description":"Jonas Sicking discovered that under some circumstances persisted XUL\nattributes are associated with the wrong URL. A malicious web site\ncould exploit this to execute arbitrary code with the privileges of\nthe user. (MFSA 2006-35, CVE-2006-2775)\n\nPaul Nickerson discovered that content-defined setters on an object\nprototype were getting called by privileged UI code. It was\ndemonstrated that this could be exploited to run arbitrary web script\nwith full user privileges (MFSA 2006-37, CVE-2006-2776). A similar\nattack was discovered by moz_bug_r_a4 that leveraged SelectionObject\nnotifications that were called in privileged context. (MFSA 2006-43,\nCVE-2006-2777)\n\nMikolaj Habryn discovered a buffer overflow in the crypto.signText()\nfunction. By tricking a user to visit a site with an SSL certificate\nwith specially crafted optional Certificate Authority name\narguments, this could potentially be exploited to execute arbitrary\ncode with the user's privileges. (MFSA 2006-38, CVE-2006-2778)\n\nThe Mozilla developer team discovered several bugs that lead to\ncrashes with memory corruption. These might be exploitable by\nmalicious web sites to execute arbitrary code with the privileges of\nthe user. (MFSA 2006-32, CVE-2006-2779, CVE-2006-2780)\n\nMasatoshi Kimura discovered a memory corruption (double-free) when\nprocessing a large VCard with invalid base64 characters in it. By\nsending a maliciously crafted set of VCards to a user, this could\npotentially be exploited to execute arbitrary code with the user's\nprivileges. (MFSA 2006-40, CVE-2006-2781)\n\nChuck McAuley reported that the fix for CVE-2006-1729 (file stealing\nby changing input type) was not sufficient to prevent all variants of\nexploitation. (MFSA 2006-41, CVE-2006-2782)\n\nMasatoshi Kimura found a way to bypass web input sanitizers which\nfilter out JavaScript. By inserting 'Unicode Byte-order-Mark (BOM)'\ncharacters into the HTML code (e. g. ''), these filters\nmight not recognize the tags anymore; however, Mozilla would still\nexecute them since BOM markers are filtered out before processing the\npage. (MFSA 2006-42, CVE-2006-2783)\n\nPaul Nickerson noticed that the fix for CVE-2005-0752 (JavaScript\nprivilege escalation on the plugins page) was not sufficient to\nprevent all variants of exploitation. (MFSA 2006-36, CVE-2006-2784)\n\nPaul Nickerson demonstrated that if an attacker could convince a user\nto right-click on a broken image and choose \"View Image\" from the\ncontext menu then he could get JavaScript to run on a site of the\nattacker's choosing. This could be used to steal login cookies or\nother confidential information from the target site. (MFSA 2006-34,\nCVE-2006-2785)\n\nKazuho Oku discovered various ways to perform HTTP response smuggling\nwhen used with certain proxy servers. Due to different interpretation\nof nonstandard HTTP headers in Mozilla and the proxy server, a\nmalicious web site can exploit this to send back two responses to one\nrequest. The second response could be used to steal login cookies or\nother sensitive data from another opened web site. (MFSA 2006-33,\nCVE-2006-2786)","is_hidden":false,"release_packages":{"hoary":[{"name":"mozilla-psm","version":"2:1.7.13-0ubuntu05.04.1","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-mailnews","version":"2:1.7.13-0ubuntu05.04.1","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-browser","version":"2:1.7.13-0ubuntu05.04.1","is_source":false,"source_link":"","version_link":""}],"breezy":[{"name":"mozilla-psm","version":"2:1.7.13-0ubuntu5.10.1","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-mailnews","version":"2:1.7.13-0ubuntu5.10.1","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-browser","version":"2:1.7.13-0ubuntu5.10.1","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2006-2775","CVE-2006-2776","CVE-2006-2777","CVE-2006-2778","CVE-2006-2779","CVE-2006-2780","CVE-2006-2781","CVE-2006-2782","CVE-2006-2783","CVE-2006-2784","CVE-2006-2785","CVE-2006-2786","CVE-2006-2787"]},{"id":"USN-297-1","title":"Thunderbird vulnerabilities","summary":"Thunderbird vulnerabilities","instructions":"After a standard system upgrade you need to restart Thunderbird to\neffect the necessary changes.\n\nPlease note that Thunderbird 1.0.8 in Ubuntu 5.10 and Ubuntu 5.04 are\nalso affected by these problems. Updates for these Ubuntu releases\nwill be delayed due to upstream dropping support for this Thunderbird\nversion. We strongly advise that you disable JavaScript to disable the\nattack vectors for most vulnerabilities if you use one of these Ubuntu\nversions.","references":[],"published":"2006-06-14T17:45:48","description":"Jonas Sicking discovered that under some circumstances persisted XUL\nattributes are associated with the wrong URL. A malicious web site\ncould exploit this to execute arbitrary code with the privileges of\nthe user. (MFSA 2006-35, CVE-2006-2775)\n\nPaul Nickerson discovered that content-defined setters on an object\nprototype were getting called by privileged UI code. It was\ndemonstrated that this could be exploited to run arbitrary web script\nwith full user privileges (MFSA 2006-37, CVE-2006-2776).\n\nMikolaj Habryn discovered a buffer overflow in the crypto.signText()\nfunction. By sending an email with malicious JavaScript to an user,\nand that user enabled JavaScript in Thunderbird (which is not the\ndefault and not recommended), this could potentially be exploited to\nexecute arbitrary code with the user's privileges. (MFSA 2006-38,\nCVE-2006-2778)\n\nThe Mozilla developer team discovered several bugs that lead to\ncrashes with memory corruption. These might be exploitable by\nmalicious web sites to execute arbitrary code with the privileges of\nthe user. (MFSA 2006-32, CVE-2006-2779, CVE-2006-2780)\n\nMasatoshi Kimura discovered a memory corruption (double-free) when\nprocessing a large VCard with invalid base64 characters in it. By\nsending a maliciously crafted set of VCards to a user, this could\npotentially be exploited to execute arbitrary code with the user's\nprivileges. (MFSA 2006-40, CVE-2006-2781)\n\nMasatoshi Kimura found a way to bypass web input sanitizers which\nfilter out JavaScript. By inserting 'Unicode Byte-order-Mark (BOM)'\ncharacters into the HTML code (e. g. ''), these filters\nmight not recognize the tags anymore; however, Thunderbird would still\nexecute them since BOM markers are filtered out before processing a\nmail containing JavaScript. (MFSA 2006-42, CVE-2006-2783)\n\nKazuho Oku discovered various ways to perform HTTP response smuggling\nwhen used with certain proxy servers. Due to different interpretation\nof nonstandard HTTP headers in Thunderbird and the proxy server, a\nmalicious HTML email can exploit this to send back two responses to one\nrequest. The second response could be used to steal login cookies or\nother sensitive data from another opened web site. (MFSA 2006-33,\nCVE-2006-2786)\n\nIt was discovered that JavaScript run via EvalInSandbox() can escape\nthe sandbox. Malicious scripts received in emails containing\nJavaScript could use these privileges to execute arbitrary code with\nthe user's privileges. (MFSA 2006-31, CVE-2006-2787)\n\nThe \"enigmail\" plugin has been updated to work with the new\nThunderbird version.","is_hidden":false,"release_packages":{"dapper":[{"name":"mozilla-thunderbird","version":"1.5.0.4-0ubuntu6.06","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-thunderbird-enigmail","version":"2:0.94-0ubuntu4.1","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2006-2775","CVE-2006-2776","CVE-2006-2778","CVE-2006-2779","CVE-2006-2780","CVE-2006-2781","CVE-2006-2783","CVE-2006-2786","CVE-2006-2787"]},{"id":"USN-296-2","title":"Firefox vulnerabilities","summary":"Firefox vulnerabilities","instructions":"After a standard system upgrade you need to restart Firefox to effect\nthe necessary changes.","references":[],"published":"2006-07-25T17:49:50","description":"USN-296-1 fixed several vulnerabilities in Firefox for the Ubuntu 6.06\nLTS release. This update provides the corresponding fixes for Ubuntu\n5.04 and Ubuntu 5.10.\n\nFor reference, these are the details of the original USN:\n\n Jonas Sicking discovered that under some circumstances persisted XUL\n attributes are associated with the wrong URL. A malicious web site\n could exploit this to execute arbitrary code with the privileges of\n the user. (MFSA 2006-35, CVE-2006-2775)\n \n Paul Nickerson discovered that content-defined setters on an object\n prototype were getting called by privileged UI code. It was\n demonstrated that this could be exploited to run arbitrary web script\n with full user privileges (MFSA 2006-37, CVE-2006-2776). A similar\n attack was discovered by moz_bug_r_a4 that leveraged SelectionObject\n notifications that were called in privileged context. (MFSA 2006-43,\n CVE-2006-2777)\n \n Mikolaj Habryn discovered a buffer overflow in the crypto.signText()\n function. By tricking a user to visit a site with an SSL certificate\n with specially crafted optional Certificate Authority name\n arguments, this could potentially be exploited to execute arbitrary\n code with the user's privileges. (MFSA 2006-38, CVE-2006-2778)\n \n The Mozilla developer team discovered several bugs that lead to\n crashes with memory corruption. These might be exploitable by\n malicious web sites to execute arbitrary code with the privileges of\n the user. (MFSA 2006-32, CVE-2006-2779, CVE-2006-2780, CVE-2006-2788)\n \n Chuck McAuley reported that the fix for CVE-2006-1729 (file stealing\n by changing input type) was not sufficient to prevent all variants of\n exploitation. (MFSA 2006-41, CVE-2006-2782)\n \n Masatoshi Kimura found a way to bypass web input sanitizers which\n filter out JavaScript. By inserting 'Unicode Byte-order-Mark (BOM)'\n characters into the HTML code (e. g. ''), these filters\n might not recognize the tags anymore; however, Firefox would still\n execute them since BOM markers are filtered out before processing the\n page. (MFSA 2006-42, CVE-2006-2783)\n \n Paul Nickerson noticed that the fix for CVE-2005-0752 (JavaScript\n privilege escalation on the plugins page) was not sufficient to\n prevent all variants of exploitation. (MFSA 2006-36, CVE-2006-2784)\n \n Paul Nickerson demonstrated that if an attacker could convince a user\n to right-click on a broken image and choose \"View Image\" from the\n context menu then he could get JavaScript to run on a site of the\n attacker's choosing. This could be used to steal login cookies or\n other confidential information from the target site. (MFSA 2006-34,\n CVE-2006-2785)\n \n Kazuho Oku discovered various ways to perform HTTP response smuggling\n when used with certain proxy servers. Due to different interpretation\n of nonstandard HTTP headers in Firefox and the proxy server, a\n malicious web site can exploit this to send back two responses to one\n request. The second response could be used to steal login cookies or\n other sensitive data from another opened web site. (MFSA 2006-33,\n CVE-2006-2786)","is_hidden":false,"release_packages":{"hoary":[{"name":"mozilla-firefox","version":"1.0.8-0ubuntu5.04.1","is_source":false,"source_link":"","version_link":""}],"breezy":[{"name":"firefox","version":"1.0.8-0ubuntu5.10.1","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2006-2775","CVE-2006-2776","CVE-2006-2777","CVE-2006-2778","CVE-2006-2779","CVE-2006-2780","CVE-2006-2782","CVE-2006-2783","CVE-2006-2784","CVE-2006-2785","CVE-2006-2786","CVE-2006-2787"]},{"id":"USN-296-1","title":"firefox vulnerabilities","summary":"firefox vulnerabilities","instructions":"After a standard system upgrade you need to restart Firefox to effect\nthe necessary changes.\n\nPlease note that Firefox 1.0.8 in Ubuntu 5.10 and Ubuntu 5.04 are also\naffected by these problems. Updates for these Ubuntu releases will be\ndelayed due to upstream dropping support for this Firefox version. We\nstrongly advise that you disable JavaScript to disable the attack\nvectors for most vulnerabilities if you use one of these Ubuntu\nversions.","references":[],"published":"2006-06-09T22:13:38","description":"Jonas Sicking discovered that under some circumstances persisted XUL\nattributes are associated with the wrong URL. A malicious web site\ncould exploit this to execute arbitrary code with the privileges of\nthe user. (MFSA 2006-35, CVE-2006-2775)\n\nPaul Nickerson discovered that content-defined setters on an object\nprototype were getting called by privileged UI code. It was\ndemonstrated that this could be exploited to run arbitrary web script\nwith full user privileges (MFSA 2006-37, CVE-2006-2776). A similar\nattack was discovered by moz_bug_r_a4 that leveraged SelectionObject\nnotifications that were called in privileged context. (MFSA 2006-43,\nCVE-2006-2777)\n\nMikolaj Habryn discovered a buffer overflow in the crypto.signText()\nfunction. By tricking a user to visit a site with an SSL certificate\nwith specially crafted optional Certificate Authority name\narguments, this could potentially be exploited to execute arbitrary\ncode with the user's privileges. (MFSA 2006-38, CVE-2006-2778)\n\nThe Mozilla developer team discovered several bugs that lead to\ncrashes with memory corruption. These might be exploitable by\nmalicious web sites to execute arbitrary code with the privileges of\nthe user. (MFSA 2006-32, CVE-2006-2779, CVE-2006-2780, CVE-2006-2788)\n\nChuck McAuley reported that the fix for CVE-2006-1729 (file stealing\nby changing input type) was not sufficient to prevent all variants of\nexploitation. (MFSA 2006-41, CVE-2006-2782)\n\nMasatoshi Kimura found a way to bypass web input sanitizers which\nfilter out JavaScript. By inserting 'Unicode Byte-order-Mark (BOM)'\ncharacters into the HTML code (e. g. ''), these filters\nmight not recognize the tags anymore; however, Firefox would still\nexecute them since BOM markers are filtered out before processing the\npage. (MFSA 2006-42, CVE-2006-2783)\n\nPaul Nickerson noticed that the fix for CVE-2005-0752 (JavaScript\nprivilege escalation on the plugins page) was not sufficient to\nprevent all variants of exploitation. (MFSA 2006-36, CVE-2006-2784)\n\nPaul Nickerson demonstrated that if an attacker could convince a user\nto right-click on a broken image and choose \"View Image\" from the\ncontext menu then he could get JavaScript to run on a site of the\nattacker's choosing. This could be used to steal login cookies or\nother confidential information from the target site. (MFSA 2006-34,\nCVE-2006-2785)\n\nKazuho Oku discovered various ways to perform HTTP response smuggling\nwhen used with certain proxy servers. Due to different interpretation\nof nonstandard HTTP headers in Firefox and the proxy server, a\nmalicious web site can exploit this to send back two responses to one\nrequest. The second response could be used to steal login cookies or\nother sensitive data from another opened web site. (MFSA 2006-33,\nCVE-2006-2786)","is_hidden":false,"release_packages":{"dapper":[{"name":"firefox","version":"1.5.dfsg+1.5.0.4-0ubuntu6.06","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2006-2775","CVE-2006-2776","CVE-2006-2777","CVE-2006-2778","CVE-2006-2779","CVE-2006-2780","CVE-2006-2782","CVE-2006-2783","CVE-2006-2784","CVE-2006-2785","CVE-2006-2786","CVE-2006-2787","CVE-2006-2788"]}]},{"id":"CVE-2006-2785","published":"2006-06-02T19:02:00","updated_at":"2025-07-17T16:38:57.863203+00:00","description":"\nCross-site scripting (XSS) vulnerability in Mozilla Firefox before 1.5.0.4\nallows user-assisted remote attackers to inject arbitrary web script or\nHTML by tricking a user into (1) performing a \"View Image\" on a broken\nimage in which the SRC attribute contains a Javascript URL, or (2)\nselecting \"Show only this frame\" on a frame whose SRC attribute contains a\nJavascript URL.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-296-1","https://ubuntu.com/security/notices/USN-296-2","https://ubuntu.com/security/notices/USN-323-1","https://www.cve.org/CVERecord?id=CVE-2006-2785"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"dapper","status":"released","description":"1.5.dfsg+1.5.0.13~prepatch070731-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"firefox-granparadiso","source":"https://ubuntu.com/security/cve?package=firefox-granparadiso","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox-granparadiso","debian":"https://tracker.debian.org/pkg/firefox-granparadiso","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"lightning-sunbird","source":"https://ubuntu.com/security/cve?package=lightning-sunbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=lightning-sunbird","debian":"https://tracker.debian.org/pkg/lightning-sunbird","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"midbrowser","source":"https://ubuntu.com/security/cve?package=midbrowser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=midbrowser","debian":"https://tracker.debian.org/pkg/midbrowser","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mozilla-thunderbird","source":"https://ubuntu.com/security/cve?package=mozilla-thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozilla-thunderbird","debian":"https://tracker.debian.org/pkg/mozilla-thunderbird","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"xulrunner","source":"https://ubuntu.com/security/cve?package=xulrunner","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xulrunner","debian":"https://tracker.debian.org/pkg/xulrunner","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.8.0.5-4.2","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.8.0.5-4.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-323-1","USN-296-2","USN-296-1"],"notices":[{"id":"USN-323-1","title":"mozilla vulnerabilities","summary":"mozilla vulnerabilities","instructions":"After a standard system upgrade you need to restart Mozilla to effect\nthe necessary changes.","references":[],"published":"2006-07-26T02:47:37","description":"Jonas Sicking discovered that under some circumstances persisted XUL\nattributes are associated with the wrong URL. A malicious web site\ncould exploit this to execute arbitrary code with the privileges of\nthe user. (MFSA 2006-35, CVE-2006-2775)\n\nPaul Nickerson discovered that content-defined setters on an object\nprototype were getting called by privileged UI code. It was\ndemonstrated that this could be exploited to run arbitrary web script\nwith full user privileges (MFSA 2006-37, CVE-2006-2776). A similar\nattack was discovered by moz_bug_r_a4 that leveraged SelectionObject\nnotifications that were called in privileged context. (MFSA 2006-43,\nCVE-2006-2777)\n\nMikolaj Habryn discovered a buffer overflow in the crypto.signText()\nfunction. By tricking a user to visit a site with an SSL certificate\nwith specially crafted optional Certificate Authority name\narguments, this could potentially be exploited to execute arbitrary\ncode with the user's privileges. (MFSA 2006-38, CVE-2006-2778)\n\nThe Mozilla developer team discovered several bugs that lead to\ncrashes with memory corruption. These might be exploitable by\nmalicious web sites to execute arbitrary code with the privileges of\nthe user. (MFSA 2006-32, CVE-2006-2779, CVE-2006-2780)\n\nMasatoshi Kimura discovered a memory corruption (double-free) when\nprocessing a large VCard with invalid base64 characters in it. By\nsending a maliciously crafted set of VCards to a user, this could\npotentially be exploited to execute arbitrary code with the user's\nprivileges. (MFSA 2006-40, CVE-2006-2781)\n\nChuck McAuley reported that the fix for CVE-2006-1729 (file stealing\nby changing input type) was not sufficient to prevent all variants of\nexploitation. (MFSA 2006-41, CVE-2006-2782)\n\nMasatoshi Kimura found a way to bypass web input sanitizers which\nfilter out JavaScript. By inserting 'Unicode Byte-order-Mark (BOM)'\ncharacters into the HTML code (e. g. ''), these filters\nmight not recognize the tags anymore; however, Mozilla would still\nexecute them since BOM markers are filtered out before processing the\npage. (MFSA 2006-42, CVE-2006-2783)\n\nPaul Nickerson noticed that the fix for CVE-2005-0752 (JavaScript\nprivilege escalation on the plugins page) was not sufficient to\nprevent all variants of exploitation. (MFSA 2006-36, CVE-2006-2784)\n\nPaul Nickerson demonstrated that if an attacker could convince a user\nto right-click on a broken image and choose \"View Image\" from the\ncontext menu then he could get JavaScript to run on a site of the\nattacker's choosing. This could be used to steal login cookies or\nother confidential information from the target site. (MFSA 2006-34,\nCVE-2006-2785)\n\nKazuho Oku discovered various ways to perform HTTP response smuggling\nwhen used with certain proxy servers. Due to different interpretation\nof nonstandard HTTP headers in Mozilla and the proxy server, a\nmalicious web site can exploit this to send back two responses to one\nrequest. The second response could be used to steal login cookies or\nother sensitive data from another opened web site. (MFSA 2006-33,\nCVE-2006-2786)","is_hidden":false,"release_packages":{"hoary":[{"name":"mozilla-psm","version":"2:1.7.13-0ubuntu05.04.1","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-mailnews","version":"2:1.7.13-0ubuntu05.04.1","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-browser","version":"2:1.7.13-0ubuntu05.04.1","is_source":false,"source_link":"","version_link":""}],"breezy":[{"name":"mozilla-psm","version":"2:1.7.13-0ubuntu5.10.1","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-mailnews","version":"2:1.7.13-0ubuntu5.10.1","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-browser","version":"2:1.7.13-0ubuntu5.10.1","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2006-2775","CVE-2006-2776","CVE-2006-2777","CVE-2006-2778","CVE-2006-2779","CVE-2006-2780","CVE-2006-2781","CVE-2006-2782","CVE-2006-2783","CVE-2006-2784","CVE-2006-2785","CVE-2006-2786","CVE-2006-2787"]},{"id":"USN-296-2","title":"Firefox vulnerabilities","summary":"Firefox vulnerabilities","instructions":"After a standard system upgrade you need to restart Firefox to effect\nthe necessary changes.","references":[],"published":"2006-07-25T17:49:50","description":"USN-296-1 fixed several vulnerabilities in Firefox for the Ubuntu 6.06\nLTS release. This update provides the corresponding fixes for Ubuntu\n5.04 and Ubuntu 5.10.\n\nFor reference, these are the details of the original USN:\n\n Jonas Sicking discovered that under some circumstances persisted XUL\n attributes are associated with the wrong URL. A malicious web site\n could exploit this to execute arbitrary code with the privileges of\n the user. (MFSA 2006-35, CVE-2006-2775)\n \n Paul Nickerson discovered that content-defined setters on an object\n prototype were getting called by privileged UI code. It was\n demonstrated that this could be exploited to run arbitrary web script\n with full user privileges (MFSA 2006-37, CVE-2006-2776). A similar\n attack was discovered by moz_bug_r_a4 that leveraged SelectionObject\n notifications that were called in privileged context. (MFSA 2006-43,\n CVE-2006-2777)\n \n Mikolaj Habryn discovered a buffer overflow in the crypto.signText()\n function. By tricking a user to visit a site with an SSL certificate\n with specially crafted optional Certificate Authority name\n arguments, this could potentially be exploited to execute arbitrary\n code with the user's privileges. (MFSA 2006-38, CVE-2006-2778)\n \n The Mozilla developer team discovered several bugs that lead to\n crashes with memory corruption. These might be exploitable by\n malicious web sites to execute arbitrary code with the privileges of\n the user. (MFSA 2006-32, CVE-2006-2779, CVE-2006-2780, CVE-2006-2788)\n \n Chuck McAuley reported that the fix for CVE-2006-1729 (file stealing\n by changing input type) was not sufficient to prevent all variants of\n exploitation. (MFSA 2006-41, CVE-2006-2782)\n \n Masatoshi Kimura found a way to bypass web input sanitizers which\n filter out JavaScript. By inserting 'Unicode Byte-order-Mark (BOM)'\n characters into the HTML code (e. g. ''), these filters\n might not recognize the tags anymore; however, Firefox would still\n execute them since BOM markers are filtered out before processing the\n page. (MFSA 2006-42, CVE-2006-2783)\n \n Paul Nickerson noticed that the fix for CVE-2005-0752 (JavaScript\n privilege escalation on the plugins page) was not sufficient to\n prevent all variants of exploitation. (MFSA 2006-36, CVE-2006-2784)\n \n Paul Nickerson demonstrated that if an attacker could convince a user\n to right-click on a broken image and choose \"View Image\" from the\n context menu then he could get JavaScript to run on a site of the\n attacker's choosing. This could be used to steal login cookies or\n other confidential information from the target site. (MFSA 2006-34,\n CVE-2006-2785)\n \n Kazuho Oku discovered various ways to perform HTTP response smuggling\n when used with certain proxy servers. Due to different interpretation\n of nonstandard HTTP headers in Firefox and the proxy server, a\n malicious web site can exploit this to send back two responses to one\n request. The second response could be used to steal login cookies or\n other sensitive data from another opened web site. (MFSA 2006-33,\n CVE-2006-2786)","is_hidden":false,"release_packages":{"hoary":[{"name":"mozilla-firefox","version":"1.0.8-0ubuntu5.04.1","is_source":false,"source_link":"","version_link":""}],"breezy":[{"name":"firefox","version":"1.0.8-0ubuntu5.10.1","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2006-2775","CVE-2006-2776","CVE-2006-2777","CVE-2006-2778","CVE-2006-2779","CVE-2006-2780","CVE-2006-2782","CVE-2006-2783","CVE-2006-2784","CVE-2006-2785","CVE-2006-2786","CVE-2006-2787"]},{"id":"USN-296-1","title":"firefox vulnerabilities","summary":"firefox vulnerabilities","instructions":"After a standard system upgrade you need to restart Firefox to effect\nthe necessary changes.\n\nPlease note that Firefox 1.0.8 in Ubuntu 5.10 and Ubuntu 5.04 are also\naffected by these problems. Updates for these Ubuntu releases will be\ndelayed due to upstream dropping support for this Firefox version. We\nstrongly advise that you disable JavaScript to disable the attack\nvectors for most vulnerabilities if you use one of these Ubuntu\nversions.","references":[],"published":"2006-06-09T22:13:38","description":"Jonas Sicking discovered that under some circumstances persisted XUL\nattributes are associated with the wrong URL. A malicious web site\ncould exploit this to execute arbitrary code with the privileges of\nthe user. (MFSA 2006-35, CVE-2006-2775)\n\nPaul Nickerson discovered that content-defined setters on an object\nprototype were getting called by privileged UI code. It was\ndemonstrated that this could be exploited to run arbitrary web script\nwith full user privileges (MFSA 2006-37, CVE-2006-2776). A similar\nattack was discovered by moz_bug_r_a4 that leveraged SelectionObject\nnotifications that were called in privileged context. (MFSA 2006-43,\nCVE-2006-2777)\n\nMikolaj Habryn discovered a buffer overflow in the crypto.signText()\nfunction. By tricking a user to visit a site with an SSL certificate\nwith specially crafted optional Certificate Authority name\narguments, this could potentially be exploited to execute arbitrary\ncode with the user's privileges. (MFSA 2006-38, CVE-2006-2778)\n\nThe Mozilla developer team discovered several bugs that lead to\ncrashes with memory corruption. These might be exploitable by\nmalicious web sites to execute arbitrary code with the privileges of\nthe user. (MFSA 2006-32, CVE-2006-2779, CVE-2006-2780, CVE-2006-2788)\n\nChuck McAuley reported that the fix for CVE-2006-1729 (file stealing\nby changing input type) was not sufficient to prevent all variants of\nexploitation. (MFSA 2006-41, CVE-2006-2782)\n\nMasatoshi Kimura found a way to bypass web input sanitizers which\nfilter out JavaScript. By inserting 'Unicode Byte-order-Mark (BOM)'\ncharacters into the HTML code (e. g. ''), these filters\nmight not recognize the tags anymore; however, Firefox would still\nexecute them since BOM markers are filtered out before processing the\npage. (MFSA 2006-42, CVE-2006-2783)\n\nPaul Nickerson noticed that the fix for CVE-2005-0752 (JavaScript\nprivilege escalation on the plugins page) was not sufficient to\nprevent all variants of exploitation. (MFSA 2006-36, CVE-2006-2784)\n\nPaul Nickerson demonstrated that if an attacker could convince a user\nto right-click on a broken image and choose \"View Image\" from the\ncontext menu then he could get JavaScript to run on a site of the\nattacker's choosing. This could be used to steal login cookies or\nother confidential information from the target site. (MFSA 2006-34,\nCVE-2006-2785)\n\nKazuho Oku discovered various ways to perform HTTP response smuggling\nwhen used with certain proxy servers. Due to different interpretation\nof nonstandard HTTP headers in Firefox and the proxy server, a\nmalicious web site can exploit this to send back two responses to one\nrequest. The second response could be used to steal login cookies or\nother sensitive data from another opened web site. (MFSA 2006-33,\nCVE-2006-2786)","is_hidden":false,"release_packages":{"dapper":[{"name":"firefox","version":"1.5.dfsg+1.5.0.4-0ubuntu6.06","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2006-2775","CVE-2006-2776","CVE-2006-2777","CVE-2006-2778","CVE-2006-2779","CVE-2006-2780","CVE-2006-2782","CVE-2006-2783","CVE-2006-2784","CVE-2006-2785","CVE-2006-2786","CVE-2006-2787","CVE-2006-2788"]}]},{"id":"CVE-2006-2784","published":"2006-06-02T19:02:00","updated_at":"2025-07-17T16:38:57.863203+00:00","description":"\nThe PLUGINSPAGE functionality in Mozilla Firefox before 1.5.0.4 allows\nremote user-assisted attackers to execute privileged code by tricking a\nuser into installing missing plugins and selecting the \"Manual Install\"\nbutton, then using nested javascript: URLs. NOTE: the manual install\nbutton is used for downloading software from a remote web site, so this\nissue would not cross privilege boundaries if the user progresses to the\npoint of installing malicious software from the attacker-controlled site.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-296-1","https://ubuntu.com/security/notices/USN-296-2","https://ubuntu.com/security/notices/USN-297-3","https://ubuntu.com/security/notices/USN-323-1","https://www.cve.org/CVERecord?id=CVE-2006-2784"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"dapper","status":"released","description":"1.5.dfsg+1.5.0.13~prepatch070731-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"firefox-granparadiso","source":"https://ubuntu.com/security/cve?package=firefox-granparadiso","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox-granparadiso","debian":"https://tracker.debian.org/pkg/firefox-granparadiso","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"lightning-sunbird","source":"https://ubuntu.com/security/cve?package=lightning-sunbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=lightning-sunbird","debian":"https://tracker.debian.org/pkg/lightning-sunbird","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"midbrowser","source":"https://ubuntu.com/security/cve?package=midbrowser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=midbrowser","debian":"https://tracker.debian.org/pkg/midbrowser","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mozilla-thunderbird","source":"https://ubuntu.com/security/cve?package=mozilla-thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozilla-thunderbird","debian":"https://tracker.debian.org/pkg/mozilla-thunderbird","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"xulrunner","source":"https://ubuntu.com/security/cve?package=xulrunner","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xulrunner","debian":"https://tracker.debian.org/pkg/xulrunner","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.8.0.5-4.2","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.8.0.5-4.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-323-1","USN-297-3","USN-296-2","USN-296-1"],"notices":[{"id":"USN-323-1","title":"mozilla vulnerabilities","summary":"mozilla vulnerabilities","instructions":"After a standard system upgrade you need to restart Mozilla to effect\nthe necessary changes.","references":[],"published":"2006-07-26T02:47:37","description":"Jonas Sicking discovered that under some circumstances persisted XUL\nattributes are associated with the wrong URL. A malicious web site\ncould exploit this to execute arbitrary code with the privileges of\nthe user. (MFSA 2006-35, CVE-2006-2775)\n\nPaul Nickerson discovered that content-defined setters on an object\nprototype were getting called by privileged UI code. It was\ndemonstrated that this could be exploited to run arbitrary web script\nwith full user privileges (MFSA 2006-37, CVE-2006-2776). A similar\nattack was discovered by moz_bug_r_a4 that leveraged SelectionObject\nnotifications that were called in privileged context. (MFSA 2006-43,\nCVE-2006-2777)\n\nMikolaj Habryn discovered a buffer overflow in the crypto.signText()\nfunction. By tricking a user to visit a site with an SSL certificate\nwith specially crafted optional Certificate Authority name\narguments, this could potentially be exploited to execute arbitrary\ncode with the user's privileges. (MFSA 2006-38, CVE-2006-2778)\n\nThe Mozilla developer team discovered several bugs that lead to\ncrashes with memory corruption. These might be exploitable by\nmalicious web sites to execute arbitrary code with the privileges of\nthe user. (MFSA 2006-32, CVE-2006-2779, CVE-2006-2780)\n\nMasatoshi Kimura discovered a memory corruption (double-free) when\nprocessing a large VCard with invalid base64 characters in it. By\nsending a maliciously crafted set of VCards to a user, this could\npotentially be exploited to execute arbitrary code with the user's\nprivileges. (MFSA 2006-40, CVE-2006-2781)\n\nChuck McAuley reported that the fix for CVE-2006-1729 (file stealing\nby changing input type) was not sufficient to prevent all variants of\nexploitation. (MFSA 2006-41, CVE-2006-2782)\n\nMasatoshi Kimura found a way to bypass web input sanitizers which\nfilter out JavaScript. By inserting 'Unicode Byte-order-Mark (BOM)'\ncharacters into the HTML code (e. g. ''), these filters\nmight not recognize the tags anymore; however, Mozilla would still\nexecute them since BOM markers are filtered out before processing the\npage. (MFSA 2006-42, CVE-2006-2783)\n\nPaul Nickerson noticed that the fix for CVE-2005-0752 (JavaScript\nprivilege escalation on the plugins page) was not sufficient to\nprevent all variants of exploitation. (MFSA 2006-36, CVE-2006-2784)\n\nPaul Nickerson demonstrated that if an attacker could convince a user\nto right-click on a broken image and choose \"View Image\" from the\ncontext menu then he could get JavaScript to run on a site of the\nattacker's choosing. This could be used to steal login cookies or\nother confidential information from the target site. (MFSA 2006-34,\nCVE-2006-2785)\n\nKazuho Oku discovered various ways to perform HTTP response smuggling\nwhen used with certain proxy servers. Due to different interpretation\nof nonstandard HTTP headers in Mozilla and the proxy server, a\nmalicious web site can exploit this to send back two responses to one\nrequest. The second response could be used to steal login cookies or\nother sensitive data from another opened web site. (MFSA 2006-33,\nCVE-2006-2786)","is_hidden":false,"release_packages":{"hoary":[{"name":"mozilla-psm","version":"2:1.7.13-0ubuntu05.04.1","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-mailnews","version":"2:1.7.13-0ubuntu05.04.1","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-browser","version":"2:1.7.13-0ubuntu05.04.1","is_source":false,"source_link":"","version_link":""}],"breezy":[{"name":"mozilla-psm","version":"2:1.7.13-0ubuntu5.10.1","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-mailnews","version":"2:1.7.13-0ubuntu5.10.1","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-browser","version":"2:1.7.13-0ubuntu5.10.1","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2006-2775","CVE-2006-2776","CVE-2006-2777","CVE-2006-2778","CVE-2006-2779","CVE-2006-2780","CVE-2006-2781","CVE-2006-2782","CVE-2006-2783","CVE-2006-2784","CVE-2006-2785","CVE-2006-2786","CVE-2006-2787"]},{"id":"USN-297-3","title":"Thunderbird vulnerabilities","summary":"Thunderbird vulnerabilities","instructions":"After a standard system upgrade you need to restart Thunderbird to\neffect the necessary changes.","references":[],"published":"2006-07-26T17:25:23","description":"USN-297-1 fixed several vulnerabilities in Thunderbird for the Ubuntu\n6.06 LTS release. This update provides the corresponding fixes for\nUbuntu 5.04 and Ubuntu 5.10.\n\nFor reference, these are the details of the original USN:\n\n Jonas Sicking discovered that under some circumstances persisted XUL\n attributes are associated with the wrong URL. A malicious web site\n could exploit this to execute arbitrary code with the privileges of\n the user. (MFSA 2006-35, CVE-2006-2775)\n\n Paul Nickerson discovered that content-defined setters on an object\n prototype were getting called by privileged UI code. It was\n demonstrated that this could be exploited to run arbitrary web\n script with full user privileges (MFSA 2006-37, CVE-2006-2776).\n\n Mikolaj Habryn discovered a buffer overflow in the crypto.signText()\n function. By sending an email with malicious JavaScript to an user,\n and that user enabled JavaScript in Thunderbird (which is not the\n default and not recommended), this could potentially be exploited to\n execute arbitrary code with the user's privileges. (MFSA 2006-38,\n CVE-2006-2778)\n\n The Mozilla developer team discovered several bugs that lead to\n crashes with memory corruption. These might be exploitable by\n malicious web sites to execute arbitrary code with the privileges of\n the user. (MFSA 2006-32, CVE-2006-2779, CVE-2006-2780)\n\n Masatoshi Kimura discovered a memory corruption (double-free) when\n processing a large VCard with invalid base64 characters in it. By\n sending a maliciously crafted set of VCards to a user, this could\n potentially be exploited to execute arbitrary code with the user's\n privileges. (MFSA 2006-40, CVE-2006-2781)\n\n Masatoshi Kimura found a way to bypass web input sanitizers which\n filter out JavaScript. By inserting 'Unicode Byte-order-Mark (BOM)'\n characters into the HTML code (e. g. ''), these filters\n might not recognize the tags anymore; however, Thunderbird would\n still execute them since BOM markers are filtered out before\n processing a mail containing JavaScript. (MFSA 2006-42,\n CVE-2006-2783)\n\n Kazuho Oku discovered various ways to perform HTTP response\n smuggling when used with certain proxy servers. Due to different\n interpretation of nonstandard HTTP headers in Thunderbird and the\n proxy server, a malicious HTML email can exploit this to send back\n two responses to one request. The second response could be used to\n steal login cookies or other sensitive data from another opened web\n site. (MFSA 2006-33, CVE-2006-2786)\n\n It was discovered that JavaScript run via EvalInSandbox() can escape\n the sandbox. Malicious scripts received in emails containing\n JavaScript could use these privileges to execute arbitrary code with\n the user's privileges. (MFSA 2006-31, CVE-2006-2787)","is_hidden":false,"release_packages":{"hoary":[{"name":"mozilla-thunderbird","version":"1.0.8-0ubuntu05.04.1","is_source":false,"source_link":"","version_link":""}],"breezy":[{"name":"mozilla-thunderbird","version":"1.0.8-0ubuntu05.10.2","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2006-2775","CVE-2006-2776","CVE-2006-2778","CVE-2006-2779","CVE-2006-2780","CVE-2006-2781","CVE-2006-2783","CVE-2006-2784","CVE-2006-2787"]},{"id":"USN-296-2","title":"Firefox vulnerabilities","summary":"Firefox vulnerabilities","instructions":"After a standard system upgrade you need to restart Firefox to effect\nthe necessary changes.","references":[],"published":"2006-07-25T17:49:50","description":"USN-296-1 fixed several vulnerabilities in Firefox for the Ubuntu 6.06\nLTS release. This update provides the corresponding fixes for Ubuntu\n5.04 and Ubuntu 5.10.\n\nFor reference, these are the details of the original USN:\n\n Jonas Sicking discovered that under some circumstances persisted XUL\n attributes are associated with the wrong URL. A malicious web site\n could exploit this to execute arbitrary code with the privileges of\n the user. (MFSA 2006-35, CVE-2006-2775)\n \n Paul Nickerson discovered that content-defined setters on an object\n prototype were getting called by privileged UI code. It was\n demonstrated that this could be exploited to run arbitrary web script\n with full user privileges (MFSA 2006-37, CVE-2006-2776). A similar\n attack was discovered by moz_bug_r_a4 that leveraged SelectionObject\n notifications that were called in privileged context. (MFSA 2006-43,\n CVE-2006-2777)\n \n Mikolaj Habryn discovered a buffer overflow in the crypto.signText()\n function. By tricking a user to visit a site with an SSL certificate\n with specially crafted optional Certificate Authority name\n arguments, this could potentially be exploited to execute arbitrary\n code with the user's privileges. (MFSA 2006-38, CVE-2006-2778)\n \n The Mozilla developer team discovered several bugs that lead to\n crashes with memory corruption. These might be exploitable by\n malicious web sites to execute arbitrary code with the privileges of\n the user. (MFSA 2006-32, CVE-2006-2779, CVE-2006-2780, CVE-2006-2788)\n \n Chuck McAuley reported that the fix for CVE-2006-1729 (file stealing\n by changing input type) was not sufficient to prevent all variants of\n exploitation. (MFSA 2006-41, CVE-2006-2782)\n \n Masatoshi Kimura found a way to bypass web input sanitizers which\n filter out JavaScript. By inserting 'Unicode Byte-order-Mark (BOM)'\n characters into the HTML code (e. g. ''), these filters\n might not recognize the tags anymore; however, Firefox would still\n execute them since BOM markers are filtered out before processing the\n page. (MFSA 2006-42, CVE-2006-2783)\n \n Paul Nickerson noticed that the fix for CVE-2005-0752 (JavaScript\n privilege escalation on the plugins page) was not sufficient to\n prevent all variants of exploitation. (MFSA 2006-36, CVE-2006-2784)\n \n Paul Nickerson demonstrated that if an attacker could convince a user\n to right-click on a broken image and choose \"View Image\" from the\n context menu then he could get JavaScript to run on a site of the\n attacker's choosing. This could be used to steal login cookies or\n other confidential information from the target site. (MFSA 2006-34,\n CVE-2006-2785)\n \n Kazuho Oku discovered various ways to perform HTTP response smuggling\n when used with certain proxy servers. Due to different interpretation\n of nonstandard HTTP headers in Firefox and the proxy server, a\n malicious web site can exploit this to send back two responses to one\n request. The second response could be used to steal login cookies or\n other sensitive data from another opened web site. (MFSA 2006-33,\n CVE-2006-2786)","is_hidden":false,"release_packages":{"hoary":[{"name":"mozilla-firefox","version":"1.0.8-0ubuntu5.04.1","is_source":false,"source_link":"","version_link":""}],"breezy":[{"name":"firefox","version":"1.0.8-0ubuntu5.10.1","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2006-2775","CVE-2006-2776","CVE-2006-2777","CVE-2006-2778","CVE-2006-2779","CVE-2006-2780","CVE-2006-2782","CVE-2006-2783","CVE-2006-2784","CVE-2006-2785","CVE-2006-2786","CVE-2006-2787"]},{"id":"USN-296-1","title":"firefox vulnerabilities","summary":"firefox vulnerabilities","instructions":"After a standard system upgrade you need to restart Firefox to effect\nthe necessary changes.\n\nPlease note that Firefox 1.0.8 in Ubuntu 5.10 and Ubuntu 5.04 are also\naffected by these problems. Updates for these Ubuntu releases will be\ndelayed due to upstream dropping support for this Firefox version. We\nstrongly advise that you disable JavaScript to disable the attack\nvectors for most vulnerabilities if you use one of these Ubuntu\nversions.","references":[],"published":"2006-06-09T22:13:38","description":"Jonas Sicking discovered that under some circumstances persisted XUL\nattributes are associated with the wrong URL. A malicious web site\ncould exploit this to execute arbitrary code with the privileges of\nthe user. (MFSA 2006-35, CVE-2006-2775)\n\nPaul Nickerson discovered that content-defined setters on an object\nprototype were getting called by privileged UI code. It was\ndemonstrated that this could be exploited to run arbitrary web script\nwith full user privileges (MFSA 2006-37, CVE-2006-2776). A similar\nattack was discovered by moz_bug_r_a4 that leveraged SelectionObject\nnotifications that were called in privileged context. (MFSA 2006-43,\nCVE-2006-2777)\n\nMikolaj Habryn discovered a buffer overflow in the crypto.signText()\nfunction. By tricking a user to visit a site with an SSL certificate\nwith specially crafted optional Certificate Authority name\narguments, this could potentially be exploited to execute arbitrary\ncode with the user's privileges. (MFSA 2006-38, CVE-2006-2778)\n\nThe Mozilla developer team discovered several bugs that lead to\ncrashes with memory corruption. These might be exploitable by\nmalicious web sites to execute arbitrary code with the privileges of\nthe user. (MFSA 2006-32, CVE-2006-2779, CVE-2006-2780, CVE-2006-2788)\n\nChuck McAuley reported that the fix for CVE-2006-1729 (file stealing\nby changing input type) was not sufficient to prevent all variants of\nexploitation. (MFSA 2006-41, CVE-2006-2782)\n\nMasatoshi Kimura found a way to bypass web input sanitizers which\nfilter out JavaScript. By inserting 'Unicode Byte-order-Mark (BOM)'\ncharacters into the HTML code (e. g. ''), these filters\nmight not recognize the tags anymore; however, Firefox would still\nexecute them since BOM markers are filtered out before processing the\npage. (MFSA 2006-42, CVE-2006-2783)\n\nPaul Nickerson noticed that the fix for CVE-2005-0752 (JavaScript\nprivilege escalation on the plugins page) was not sufficient to\nprevent all variants of exploitation. (MFSA 2006-36, CVE-2006-2784)\n\nPaul Nickerson demonstrated that if an attacker could convince a user\nto right-click on a broken image and choose \"View Image\" from the\ncontext menu then he could get JavaScript to run on a site of the\nattacker's choosing. This could be used to steal login cookies or\nother confidential information from the target site. (MFSA 2006-34,\nCVE-2006-2785)\n\nKazuho Oku discovered various ways to perform HTTP response smuggling\nwhen used with certain proxy servers. Due to different interpretation\nof nonstandard HTTP headers in Firefox and the proxy server, a\nmalicious web site can exploit this to send back two responses to one\nrequest. The second response could be used to steal login cookies or\nother sensitive data from another opened web site. (MFSA 2006-33,\nCVE-2006-2786)","is_hidden":false,"release_packages":{"dapper":[{"name":"firefox","version":"1.5.dfsg+1.5.0.4-0ubuntu6.06","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2006-2775","CVE-2006-2776","CVE-2006-2777","CVE-2006-2778","CVE-2006-2779","CVE-2006-2780","CVE-2006-2782","CVE-2006-2783","CVE-2006-2784","CVE-2006-2785","CVE-2006-2786","CVE-2006-2787","CVE-2006-2788"]}]},{"id":"CVE-2006-2783","published":"2006-06-02T19:02:00","updated_at":"2025-07-17T16:38:57.863203+00:00","description":"\nMozilla Firefox and Thunderbird before 1.5.0.4 strip the Unicode\nByte-order-Mark (BOM) from a UTF-8 page before the page is passed to the\nparser, which allows remote attackers to conduct cross-site scripting (XSS)\nattacks via a BOM sequence in the middle of a dangerous tag such as SCRIPT.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-296-1","https://ubuntu.com/security/notices/USN-296-2","https://ubuntu.com/security/notices/USN-297-1","https://ubuntu.com/security/notices/USN-297-3","https://ubuntu.com/security/notices/USN-323-1","https://www.cve.org/CVERecord?id=CVE-2006-2783"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"dapper","status":"released","description":"1.5.dfsg+1.5.0.13~prepatch070731-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"firefox-granparadiso","source":"https://ubuntu.com/security/cve?package=firefox-granparadiso","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox-granparadiso","debian":"https://tracker.debian.org/pkg/firefox-granparadiso","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"lightning-sunbird","source":"https://ubuntu.com/security/cve?package=lightning-sunbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=lightning-sunbird","debian":"https://tracker.debian.org/pkg/lightning-sunbird","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"midbrowser","source":"https://ubuntu.com/security/cve?package=midbrowser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=midbrowser","debian":"https://tracker.debian.org/pkg/midbrowser","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mozilla-thunderbird","source":"https://ubuntu.com/security/cve?package=mozilla-thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozilla-thunderbird","debian":"https://tracker.debian.org/pkg/mozilla-thunderbird","statuses":[{"release_codename":"dapper","status":"released","description":"1.5.0.13-0ubuntu0.6.06","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.5.0.13-0ubuntu0.6.10","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.5.0.13-0ubuntu0.7.04","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"xulrunner","source":"https://ubuntu.com/security/cve?package=xulrunner","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xulrunner","debian":"https://tracker.debian.org/pkg/xulrunner","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.8.0.5-4.2","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.8.0.5-4.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-323-1","USN-297-1","USN-297-3","USN-296-2","USN-296-1"],"notices":[{"id":"USN-323-1","title":"mozilla vulnerabilities","summary":"mozilla vulnerabilities","instructions":"After a standard system upgrade you need to restart Mozilla to effect\nthe necessary changes.","references":[],"published":"2006-07-26T02:47:37","description":"Jonas Sicking discovered that under some circumstances persisted XUL\nattributes are associated with the wrong URL. A malicious web site\ncould exploit this to execute arbitrary code with the privileges of\nthe user. (MFSA 2006-35, CVE-2006-2775)\n\nPaul Nickerson discovered that content-defined setters on an object\nprototype were getting called by privileged UI code. It was\ndemonstrated that this could be exploited to run arbitrary web script\nwith full user privileges (MFSA 2006-37, CVE-2006-2776). A similar\nattack was discovered by moz_bug_r_a4 that leveraged SelectionObject\nnotifications that were called in privileged context. (MFSA 2006-43,\nCVE-2006-2777)\n\nMikolaj Habryn discovered a buffer overflow in the crypto.signText()\nfunction. By tricking a user to visit a site with an SSL certificate\nwith specially crafted optional Certificate Authority name\narguments, this could potentially be exploited to execute arbitrary\ncode with the user's privileges. (MFSA 2006-38, CVE-2006-2778)\n\nThe Mozilla developer team discovered several bugs that lead to\ncrashes with memory corruption. These might be exploitable by\nmalicious web sites to execute arbitrary code with the privileges of\nthe user. (MFSA 2006-32, CVE-2006-2779, CVE-2006-2780)\n\nMasatoshi Kimura discovered a memory corruption (double-free) when\nprocessing a large VCard with invalid base64 characters in it. By\nsending a maliciously crafted set of VCards to a user, this could\npotentially be exploited to execute arbitrary code with the user's\nprivileges. (MFSA 2006-40, CVE-2006-2781)\n\nChuck McAuley reported that the fix for CVE-2006-1729 (file stealing\nby changing input type) was not sufficient to prevent all variants of\nexploitation. (MFSA 2006-41, CVE-2006-2782)\n\nMasatoshi Kimura found a way to bypass web input sanitizers which\nfilter out JavaScript. By inserting 'Unicode Byte-order-Mark (BOM)'\ncharacters into the HTML code (e. g. ''), these filters\nmight not recognize the tags anymore; however, Mozilla would still\nexecute them since BOM markers are filtered out before processing the\npage. (MFSA 2006-42, CVE-2006-2783)\n\nPaul Nickerson noticed that the fix for CVE-2005-0752 (JavaScript\nprivilege escalation on the plugins page) was not sufficient to\nprevent all variants of exploitation. (MFSA 2006-36, CVE-2006-2784)\n\nPaul Nickerson demonstrated that if an attacker could convince a user\nto right-click on a broken image and choose \"View Image\" from the\ncontext menu then he could get JavaScript to run on a site of the\nattacker's choosing. This could be used to steal login cookies or\nother confidential information from the target site. (MFSA 2006-34,\nCVE-2006-2785)\n\nKazuho Oku discovered various ways to perform HTTP response smuggling\nwhen used with certain proxy servers. Due to different interpretation\nof nonstandard HTTP headers in Mozilla and the proxy server, a\nmalicious web site can exploit this to send back two responses to one\nrequest. The second response could be used to steal login cookies or\nother sensitive data from another opened web site. (MFSA 2006-33,\nCVE-2006-2786)","is_hidden":false,"release_packages":{"hoary":[{"name":"mozilla-psm","version":"2:1.7.13-0ubuntu05.04.1","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-mailnews","version":"2:1.7.13-0ubuntu05.04.1","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-browser","version":"2:1.7.13-0ubuntu05.04.1","is_source":false,"source_link":"","version_link":""}],"breezy":[{"name":"mozilla-psm","version":"2:1.7.13-0ubuntu5.10.1","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-mailnews","version":"2:1.7.13-0ubuntu5.10.1","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-browser","version":"2:1.7.13-0ubuntu5.10.1","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2006-2775","CVE-2006-2776","CVE-2006-2777","CVE-2006-2778","CVE-2006-2779","CVE-2006-2780","CVE-2006-2781","CVE-2006-2782","CVE-2006-2783","CVE-2006-2784","CVE-2006-2785","CVE-2006-2786","CVE-2006-2787"]},{"id":"USN-297-1","title":"Thunderbird vulnerabilities","summary":"Thunderbird vulnerabilities","instructions":"After a standard system upgrade you need to restart Thunderbird to\neffect the necessary changes.\n\nPlease note that Thunderbird 1.0.8 in Ubuntu 5.10 and Ubuntu 5.04 are\nalso affected by these problems. Updates for these Ubuntu releases\nwill be delayed due to upstream dropping support for this Thunderbird\nversion. We strongly advise that you disable JavaScript to disable the\nattack vectors for most vulnerabilities if you use one of these Ubuntu\nversions.","references":[],"published":"2006-06-14T17:45:48","description":"Jonas Sicking discovered that under some circumstances persisted XUL\nattributes are associated with the wrong URL. A malicious web site\ncould exploit this to execute arbitrary code with the privileges of\nthe user. (MFSA 2006-35, CVE-2006-2775)\n\nPaul Nickerson discovered that content-defined setters on an object\nprototype were getting called by privileged UI code. It was\ndemonstrated that this could be exploited to run arbitrary web script\nwith full user privileges (MFSA 2006-37, CVE-2006-2776).\n\nMikolaj Habryn discovered a buffer overflow in the crypto.signText()\nfunction. By sending an email with malicious JavaScript to an user,\nand that user enabled JavaScript in Thunderbird (which is not the\ndefault and not recommended), this could potentially be exploited to\nexecute arbitrary code with the user's privileges. (MFSA 2006-38,\nCVE-2006-2778)\n\nThe Mozilla developer team discovered several bugs that lead to\ncrashes with memory corruption. These might be exploitable by\nmalicious web sites to execute arbitrary code with the privileges of\nthe user. (MFSA 2006-32, CVE-2006-2779, CVE-2006-2780)\n\nMasatoshi Kimura discovered a memory corruption (double-free) when\nprocessing a large VCard with invalid base64 characters in it. By\nsending a maliciously crafted set of VCards to a user, this could\npotentially be exploited to execute arbitrary code with the user's\nprivileges. (MFSA 2006-40, CVE-2006-2781)\n\nMasatoshi Kimura found a way to bypass web input sanitizers which\nfilter out JavaScript. By inserting 'Unicode Byte-order-Mark (BOM)'\ncharacters into the HTML code (e. g. ''), these filters\nmight not recognize the tags anymore; however, Thunderbird would still\nexecute them since BOM markers are filtered out before processing a\nmail containing JavaScript. (MFSA 2006-42, CVE-2006-2783)\n\nKazuho Oku discovered various ways to perform HTTP response smuggling\nwhen used with certain proxy servers. Due to different interpretation\nof nonstandard HTTP headers in Thunderbird and the proxy server, a\nmalicious HTML email can exploit this to send back two responses to one\nrequest. The second response could be used to steal login cookies or\nother sensitive data from another opened web site. (MFSA 2006-33,\nCVE-2006-2786)\n\nIt was discovered that JavaScript run via EvalInSandbox() can escape\nthe sandbox. Malicious scripts received in emails containing\nJavaScript could use these privileges to execute arbitrary code with\nthe user's privileges. (MFSA 2006-31, CVE-2006-2787)\n\nThe \"enigmail\" plugin has been updated to work with the new\nThunderbird version.","is_hidden":false,"release_packages":{"dapper":[{"name":"mozilla-thunderbird","version":"1.5.0.4-0ubuntu6.06","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-thunderbird-enigmail","version":"2:0.94-0ubuntu4.1","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2006-2775","CVE-2006-2776","CVE-2006-2778","CVE-2006-2779","CVE-2006-2780","CVE-2006-2781","CVE-2006-2783","CVE-2006-2786","CVE-2006-2787"]},{"id":"USN-297-3","title":"Thunderbird vulnerabilities","summary":"Thunderbird vulnerabilities","instructions":"After a standard system upgrade you need to restart Thunderbird to\neffect the necessary changes.","references":[],"published":"2006-07-26T17:25:23","description":"USN-297-1 fixed several vulnerabilities in Thunderbird for the Ubuntu\n6.06 LTS release. This update provides the corresponding fixes for\nUbuntu 5.04 and Ubuntu 5.10.\n\nFor reference, these are the details of the original USN:\n\n Jonas Sicking discovered that under some circumstances persisted XUL\n attributes are associated with the wrong URL. A malicious web site\n could exploit this to execute arbitrary code with the privileges of\n the user. (MFSA 2006-35, CVE-2006-2775)\n\n Paul Nickerson discovered that content-defined setters on an object\n prototype were getting called by privileged UI code. It was\n demonstrated that this could be exploited to run arbitrary web\n script with full user privileges (MFSA 2006-37, CVE-2006-2776).\n\n Mikolaj Habryn discovered a buffer overflow in the crypto.signText()\n function. By sending an email with malicious JavaScript to an user,\n and that user enabled JavaScript in Thunderbird (which is not the\n default and not recommended), this could potentially be exploited to\n execute arbitrary code with the user's privileges. (MFSA 2006-38,\n CVE-2006-2778)\n\n The Mozilla developer team discovered several bugs that lead to\n crashes with memory corruption. These might be exploitable by\n malicious web sites to execute arbitrary code with the privileges of\n the user. (MFSA 2006-32, CVE-2006-2779, CVE-2006-2780)\n\n Masatoshi Kimura discovered a memory corruption (double-free) when\n processing a large VCard with invalid base64 characters in it. By\n sending a maliciously crafted set of VCards to a user, this could\n potentially be exploited to execute arbitrary code with the user's\n privileges. (MFSA 2006-40, CVE-2006-2781)\n\n Masatoshi Kimura found a way to bypass web input sanitizers which\n filter out JavaScript. By inserting 'Unicode Byte-order-Mark (BOM)'\n characters into the HTML code (e. g. ''), these filters\n might not recognize the tags anymore; however, Thunderbird would\n still execute them since BOM markers are filtered out before\n processing a mail containing JavaScript. (MFSA 2006-42,\n CVE-2006-2783)\n\n Kazuho Oku discovered various ways to perform HTTP response\n smuggling when used with certain proxy servers. Due to different\n interpretation of nonstandard HTTP headers in Thunderbird and the\n proxy server, a malicious HTML email can exploit this to send back\n two responses to one request. The second response could be used to\n steal login cookies or other sensitive data from another opened web\n site. (MFSA 2006-33, CVE-2006-2786)\n\n It was discovered that JavaScript run via EvalInSandbox() can escape\n the sandbox. Malicious scripts received in emails containing\n JavaScript could use these privileges to execute arbitrary code with\n the user's privileges. (MFSA 2006-31, CVE-2006-2787)","is_hidden":false,"release_packages":{"hoary":[{"name":"mozilla-thunderbird","version":"1.0.8-0ubuntu05.04.1","is_source":false,"source_link":"","version_link":""}],"breezy":[{"name":"mozilla-thunderbird","version":"1.0.8-0ubuntu05.10.2","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2006-2775","CVE-2006-2776","CVE-2006-2778","CVE-2006-2779","CVE-2006-2780","CVE-2006-2781","CVE-2006-2783","CVE-2006-2784","CVE-2006-2787"]},{"id":"USN-296-2","title":"Firefox vulnerabilities","summary":"Firefox vulnerabilities","instructions":"After a standard system upgrade you need to restart Firefox to effect\nthe necessary changes.","references":[],"published":"2006-07-25T17:49:50","description":"USN-296-1 fixed several vulnerabilities in Firefox for the Ubuntu 6.06\nLTS release. This update provides the corresponding fixes for Ubuntu\n5.04 and Ubuntu 5.10.\n\nFor reference, these are the details of the original USN:\n\n Jonas Sicking discovered that under some circumstances persisted XUL\n attributes are associated with the wrong URL. A malicious web site\n could exploit this to execute arbitrary code with the privileges of\n the user. (MFSA 2006-35, CVE-2006-2775)\n \n Paul Nickerson discovered that content-defined setters on an object\n prototype were getting called by privileged UI code. It was\n demonstrated that this could be exploited to run arbitrary web script\n with full user privileges (MFSA 2006-37, CVE-2006-2776). A similar\n attack was discovered by moz_bug_r_a4 that leveraged SelectionObject\n notifications that were called in privileged context. (MFSA 2006-43,\n CVE-2006-2777)\n \n Mikolaj Habryn discovered a buffer overflow in the crypto.signText()\n function. By tricking a user to visit a site with an SSL certificate\n with specially crafted optional Certificate Authority name\n arguments, this could potentially be exploited to execute arbitrary\n code with the user's privileges. (MFSA 2006-38, CVE-2006-2778)\n \n The Mozilla developer team discovered several bugs that lead to\n crashes with memory corruption. These might be exploitable by\n malicious web sites to execute arbitrary code with the privileges of\n the user. (MFSA 2006-32, CVE-2006-2779, CVE-2006-2780, CVE-2006-2788)\n \n Chuck McAuley reported that the fix for CVE-2006-1729 (file stealing\n by changing input type) was not sufficient to prevent all variants of\n exploitation. (MFSA 2006-41, CVE-2006-2782)\n \n Masatoshi Kimura found a way to bypass web input sanitizers which\n filter out JavaScript. By inserting 'Unicode Byte-order-Mark (BOM)'\n characters into the HTML code (e. g. ''), these filters\n might not recognize the tags anymore; however, Firefox would still\n execute them since BOM markers are filtered out before processing the\n page. (MFSA 2006-42, CVE-2006-2783)\n \n Paul Nickerson noticed that the fix for CVE-2005-0752 (JavaScript\n privilege escalation on the plugins page) was not sufficient to\n prevent all variants of exploitation. (MFSA 2006-36, CVE-2006-2784)\n \n Paul Nickerson demonstrated that if an attacker could convince a user\n to right-click on a broken image and choose \"View Image\" from the\n context menu then he could get JavaScript to run on a site of the\n attacker's choosing. This could be used to steal login cookies or\n other confidential information from the target site. (MFSA 2006-34,\n CVE-2006-2785)\n \n Kazuho Oku discovered various ways to perform HTTP response smuggling\n when used with certain proxy servers. Due to different interpretation\n of nonstandard HTTP headers in Firefox and the proxy server, a\n malicious web site can exploit this to send back two responses to one\n request. The second response could be used to steal login cookies or\n other sensitive data from another opened web site. (MFSA 2006-33,\n CVE-2006-2786)","is_hidden":false,"release_packages":{"hoary":[{"name":"mozilla-firefox","version":"1.0.8-0ubuntu5.04.1","is_source":false,"source_link":"","version_link":""}],"breezy":[{"name":"firefox","version":"1.0.8-0ubuntu5.10.1","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2006-2775","CVE-2006-2776","CVE-2006-2777","CVE-2006-2778","CVE-2006-2779","CVE-2006-2780","CVE-2006-2782","CVE-2006-2783","CVE-2006-2784","CVE-2006-2785","CVE-2006-2786","CVE-2006-2787"]},{"id":"USN-296-1","title":"firefox vulnerabilities","summary":"firefox vulnerabilities","instructions":"After a standard system upgrade you need to restart Firefox to effect\nthe necessary changes.\n\nPlease note that Firefox 1.0.8 in Ubuntu 5.10 and Ubuntu 5.04 are also\naffected by these problems. Updates for these Ubuntu releases will be\ndelayed due to upstream dropping support for this Firefox version. We\nstrongly advise that you disable JavaScript to disable the attack\nvectors for most vulnerabilities if you use one of these Ubuntu\nversions.","references":[],"published":"2006-06-09T22:13:38","description":"Jonas Sicking discovered that under some circumstances persisted XUL\nattributes are associated with the wrong URL. A malicious web site\ncould exploit this to execute arbitrary code with the privileges of\nthe user. (MFSA 2006-35, CVE-2006-2775)\n\nPaul Nickerson discovered that content-defined setters on an object\nprototype were getting called by privileged UI code. It was\ndemonstrated that this could be exploited to run arbitrary web script\nwith full user privileges (MFSA 2006-37, CVE-2006-2776). A similar\nattack was discovered by moz_bug_r_a4 that leveraged SelectionObject\nnotifications that were called in privileged context. (MFSA 2006-43,\nCVE-2006-2777)\n\nMikolaj Habryn discovered a buffer overflow in the crypto.signText()\nfunction. By tricking a user to visit a site with an SSL certificate\nwith specially crafted optional Certificate Authority name\narguments, this could potentially be exploited to execute arbitrary\ncode with the user's privileges. (MFSA 2006-38, CVE-2006-2778)\n\nThe Mozilla developer team discovered several bugs that lead to\ncrashes with memory corruption. These might be exploitable by\nmalicious web sites to execute arbitrary code with the privileges of\nthe user. (MFSA 2006-32, CVE-2006-2779, CVE-2006-2780, CVE-2006-2788)\n\nChuck McAuley reported that the fix for CVE-2006-1729 (file stealing\nby changing input type) was not sufficient to prevent all variants of\nexploitation. (MFSA 2006-41, CVE-2006-2782)\n\nMasatoshi Kimura found a way to bypass web input sanitizers which\nfilter out JavaScript. By inserting 'Unicode Byte-order-Mark (BOM)'\ncharacters into the HTML code (e. g. ''), these filters\nmight not recognize the tags anymore; however, Firefox would still\nexecute them since BOM markers are filtered out before processing the\npage. (MFSA 2006-42, CVE-2006-2783)\n\nPaul Nickerson noticed that the fix for CVE-2005-0752 (JavaScript\nprivilege escalation on the plugins page) was not sufficient to\nprevent all variants of exploitation. (MFSA 2006-36, CVE-2006-2784)\n\nPaul Nickerson demonstrated that if an attacker could convince a user\nto right-click on a broken image and choose \"View Image\" from the\ncontext menu then he could get JavaScript to run on a site of the\nattacker's choosing. This could be used to steal login cookies or\nother confidential information from the target site. (MFSA 2006-34,\nCVE-2006-2785)\n\nKazuho Oku discovered various ways to perform HTTP response smuggling\nwhen used with certain proxy servers. Due to different interpretation\nof nonstandard HTTP headers in Firefox and the proxy server, a\nmalicious web site can exploit this to send back two responses to one\nrequest. The second response could be used to steal login cookies or\nother sensitive data from another opened web site. (MFSA 2006-33,\nCVE-2006-2786)","is_hidden":false,"release_packages":{"dapper":[{"name":"firefox","version":"1.5.dfsg+1.5.0.4-0ubuntu6.06","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2006-2775","CVE-2006-2776","CVE-2006-2777","CVE-2006-2778","CVE-2006-2779","CVE-2006-2780","CVE-2006-2782","CVE-2006-2783","CVE-2006-2784","CVE-2006-2785","CVE-2006-2786","CVE-2006-2787","CVE-2006-2788"]}]},{"id":"CVE-2006-2782","published":"2006-06-02T19:02:00","updated_at":"2025-07-17T16:38:57.863203+00:00","description":"\nFirefox 1.5.0.2 does not fix all test cases associated with CVE-2006-1729,\nwhich allows remote attackers to read arbitrary files by inserting the\ntarget filename into a text box, then turning that box into a file upload\ncontrol.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-296-1","https://ubuntu.com/security/notices/USN-296-2","https://ubuntu.com/security/notices/USN-323-1","https://www.cve.org/CVERecord?id=CVE-2006-2782"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"dapper","status":"released","description":"1.5.dfsg+1.5.0.13~prepatch070731-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"firefox-granparadiso","source":"https://ubuntu.com/security/cve?package=firefox-granparadiso","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox-granparadiso","debian":"https://tracker.debian.org/pkg/firefox-granparadiso","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"lightning-sunbird","source":"https://ubuntu.com/security/cve?package=lightning-sunbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=lightning-sunbird","debian":"https://tracker.debian.org/pkg/lightning-sunbird","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"midbrowser","source":"https://ubuntu.com/security/cve?package=midbrowser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=midbrowser","debian":"https://tracker.debian.org/pkg/midbrowser","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mozilla-thunderbird","source":"https://ubuntu.com/security/cve?package=mozilla-thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozilla-thunderbird","debian":"https://tracker.debian.org/pkg/mozilla-thunderbird","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"xulrunner","source":"https://ubuntu.com/security/cve?package=xulrunner","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xulrunner","debian":"https://tracker.debian.org/pkg/xulrunner","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.8.0.5-4.2","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.8.0.5-4.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-323-1","USN-296-2","USN-296-1"],"notices":[{"id":"USN-323-1","title":"mozilla vulnerabilities","summary":"mozilla vulnerabilities","instructions":"After a standard system upgrade you need to restart Mozilla to effect\nthe necessary changes.","references":[],"published":"2006-07-26T02:47:37","description":"Jonas Sicking discovered that under some circumstances persisted XUL\nattributes are associated with the wrong URL. A malicious web site\ncould exploit this to execute arbitrary code with the privileges of\nthe user. (MFSA 2006-35, CVE-2006-2775)\n\nPaul Nickerson discovered that content-defined setters on an object\nprototype were getting called by privileged UI code. It was\ndemonstrated that this could be exploited to run arbitrary web script\nwith full user privileges (MFSA 2006-37, CVE-2006-2776). A similar\nattack was discovered by moz_bug_r_a4 that leveraged SelectionObject\nnotifications that were called in privileged context. (MFSA 2006-43,\nCVE-2006-2777)\n\nMikolaj Habryn discovered a buffer overflow in the crypto.signText()\nfunction. By tricking a user to visit a site with an SSL certificate\nwith specially crafted optional Certificate Authority name\narguments, this could potentially be exploited to execute arbitrary\ncode with the user's privileges. (MFSA 2006-38, CVE-2006-2778)\n\nThe Mozilla developer team discovered several bugs that lead to\ncrashes with memory corruption. These might be exploitable by\nmalicious web sites to execute arbitrary code with the privileges of\nthe user. (MFSA 2006-32, CVE-2006-2779, CVE-2006-2780)\n\nMasatoshi Kimura discovered a memory corruption (double-free) when\nprocessing a large VCard with invalid base64 characters in it. By\nsending a maliciously crafted set of VCards to a user, this could\npotentially be exploited to execute arbitrary code with the user's\nprivileges. (MFSA 2006-40, CVE-2006-2781)\n\nChuck McAuley reported that the fix for CVE-2006-1729 (file stealing\nby changing input type) was not sufficient to prevent all variants of\nexploitation. (MFSA 2006-41, CVE-2006-2782)\n\nMasatoshi Kimura found a way to bypass web input sanitizers which\nfilter out JavaScript. By inserting 'Unicode Byte-order-Mark (BOM)'\ncharacters into the HTML code (e. g. ''), these filters\nmight not recognize the tags anymore; however, Mozilla would still\nexecute them since BOM markers are filtered out before processing the\npage. (MFSA 2006-42, CVE-2006-2783)\n\nPaul Nickerson noticed that the fix for CVE-2005-0752 (JavaScript\nprivilege escalation on the plugins page) was not sufficient to\nprevent all variants of exploitation. (MFSA 2006-36, CVE-2006-2784)\n\nPaul Nickerson demonstrated that if an attacker could convince a user\nto right-click on a broken image and choose \"View Image\" from the\ncontext menu then he could get JavaScript to run on a site of the\nattacker's choosing. This could be used to steal login cookies or\nother confidential information from the target site. (MFSA 2006-34,\nCVE-2006-2785)\n\nKazuho Oku discovered various ways to perform HTTP response smuggling\nwhen used with certain proxy servers. Due to different interpretation\nof nonstandard HTTP headers in Mozilla and the proxy server, a\nmalicious web site can exploit this to send back two responses to one\nrequest. The second response could be used to steal login cookies or\nother sensitive data from another opened web site. (MFSA 2006-33,\nCVE-2006-2786)","is_hidden":false,"release_packages":{"hoary":[{"name":"mozilla-psm","version":"2:1.7.13-0ubuntu05.04.1","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-mailnews","version":"2:1.7.13-0ubuntu05.04.1","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-browser","version":"2:1.7.13-0ubuntu05.04.1","is_source":false,"source_link":"","version_link":""}],"breezy":[{"name":"mozilla-psm","version":"2:1.7.13-0ubuntu5.10.1","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-mailnews","version":"2:1.7.13-0ubuntu5.10.1","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-browser","version":"2:1.7.13-0ubuntu5.10.1","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2006-2775","CVE-2006-2776","CVE-2006-2777","CVE-2006-2778","CVE-2006-2779","CVE-2006-2780","CVE-2006-2781","CVE-2006-2782","CVE-2006-2783","CVE-2006-2784","CVE-2006-2785","CVE-2006-2786","CVE-2006-2787"]},{"id":"USN-296-2","title":"Firefox vulnerabilities","summary":"Firefox vulnerabilities","instructions":"After a standard system upgrade you need to restart Firefox to effect\nthe necessary changes.","references":[],"published":"2006-07-25T17:49:50","description":"USN-296-1 fixed several vulnerabilities in Firefox for the Ubuntu 6.06\nLTS release. This update provides the corresponding fixes for Ubuntu\n5.04 and Ubuntu 5.10.\n\nFor reference, these are the details of the original USN:\n\n Jonas Sicking discovered that under some circumstances persisted XUL\n attributes are associated with the wrong URL. A malicious web site\n could exploit this to execute arbitrary code with the privileges of\n the user. (MFSA 2006-35, CVE-2006-2775)\n \n Paul Nickerson discovered that content-defined setters on an object\n prototype were getting called by privileged UI code. It was\n demonstrated that this could be exploited to run arbitrary web script\n with full user privileges (MFSA 2006-37, CVE-2006-2776). A similar\n attack was discovered by moz_bug_r_a4 that leveraged SelectionObject\n notifications that were called in privileged context. (MFSA 2006-43,\n CVE-2006-2777)\n \n Mikolaj Habryn discovered a buffer overflow in the crypto.signText()\n function. By tricking a user to visit a site with an SSL certificate\n with specially crafted optional Certificate Authority name\n arguments, this could potentially be exploited to execute arbitrary\n code with the user's privileges. (MFSA 2006-38, CVE-2006-2778)\n \n The Mozilla developer team discovered several bugs that lead to\n crashes with memory corruption. These might be exploitable by\n malicious web sites to execute arbitrary code with the privileges of\n the user. (MFSA 2006-32, CVE-2006-2779, CVE-2006-2780, CVE-2006-2788)\n \n Chuck McAuley reported that the fix for CVE-2006-1729 (file stealing\n by changing input type) was not sufficient to prevent all variants of\n exploitation. (MFSA 2006-41, CVE-2006-2782)\n \n Masatoshi Kimura found a way to bypass web input sanitizers which\n filter out JavaScript. By inserting 'Unicode Byte-order-Mark (BOM)'\n characters into the HTML code (e. g. ''), these filters\n might not recognize the tags anymore; however, Firefox would still\n execute them since BOM markers are filtered out before processing the\n page. (MFSA 2006-42, CVE-2006-2783)\n \n Paul Nickerson noticed that the fix for CVE-2005-0752 (JavaScript\n privilege escalation on the plugins page) was not sufficient to\n prevent all variants of exploitation. (MFSA 2006-36, CVE-2006-2784)\n \n Paul Nickerson demonstrated that if an attacker could convince a user\n to right-click on a broken image and choose \"View Image\" from the\n context menu then he could get JavaScript to run on a site of the\n attacker's choosing. This could be used to steal login cookies or\n other confidential information from the target site. (MFSA 2006-34,\n CVE-2006-2785)\n \n Kazuho Oku discovered various ways to perform HTTP response smuggling\n when used with certain proxy servers. Due to different interpretation\n of nonstandard HTTP headers in Firefox and the proxy server, a\n malicious web site can exploit this to send back two responses to one\n request. The second response could be used to steal login cookies or\n other sensitive data from another opened web site. (MFSA 2006-33,\n CVE-2006-2786)","is_hidden":false,"release_packages":{"hoary":[{"name":"mozilla-firefox","version":"1.0.8-0ubuntu5.04.1","is_source":false,"source_link":"","version_link":""}],"breezy":[{"name":"firefox","version":"1.0.8-0ubuntu5.10.1","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2006-2775","CVE-2006-2776","CVE-2006-2777","CVE-2006-2778","CVE-2006-2779","CVE-2006-2780","CVE-2006-2782","CVE-2006-2783","CVE-2006-2784","CVE-2006-2785","CVE-2006-2786","CVE-2006-2787"]},{"id":"USN-296-1","title":"firefox vulnerabilities","summary":"firefox vulnerabilities","instructions":"After a standard system upgrade you need to restart Firefox to effect\nthe necessary changes.\n\nPlease note that Firefox 1.0.8 in Ubuntu 5.10 and Ubuntu 5.04 are also\naffected by these problems. Updates for these Ubuntu releases will be\ndelayed due to upstream dropping support for this Firefox version. We\nstrongly advise that you disable JavaScript to disable the attack\nvectors for most vulnerabilities if you use one of these Ubuntu\nversions.","references":[],"published":"2006-06-09T22:13:38","description":"Jonas Sicking discovered that under some circumstances persisted XUL\nattributes are associated with the wrong URL. A malicious web site\ncould exploit this to execute arbitrary code with the privileges of\nthe user. (MFSA 2006-35, CVE-2006-2775)\n\nPaul Nickerson discovered that content-defined setters on an object\nprototype were getting called by privileged UI code. It was\ndemonstrated that this could be exploited to run arbitrary web script\nwith full user privileges (MFSA 2006-37, CVE-2006-2776). A similar\nattack was discovered by moz_bug_r_a4 that leveraged SelectionObject\nnotifications that were called in privileged context. (MFSA 2006-43,\nCVE-2006-2777)\n\nMikolaj Habryn discovered a buffer overflow in the crypto.signText()\nfunction. By tricking a user to visit a site with an SSL certificate\nwith specially crafted optional Certificate Authority name\narguments, this could potentially be exploited to execute arbitrary\ncode with the user's privileges. (MFSA 2006-38, CVE-2006-2778)\n\nThe Mozilla developer team discovered several bugs that lead to\ncrashes with memory corruption. These might be exploitable by\nmalicious web sites to execute arbitrary code with the privileges of\nthe user. (MFSA 2006-32, CVE-2006-2779, CVE-2006-2780, CVE-2006-2788)\n\nChuck McAuley reported that the fix for CVE-2006-1729 (file stealing\nby changing input type) was not sufficient to prevent all variants of\nexploitation. (MFSA 2006-41, CVE-2006-2782)\n\nMasatoshi Kimura found a way to bypass web input sanitizers which\nfilter out JavaScript. By inserting 'Unicode Byte-order-Mark (BOM)'\ncharacters into the HTML code (e. g. ''), these filters\nmight not recognize the tags anymore; however, Firefox would still\nexecute them since BOM markers are filtered out before processing the\npage. (MFSA 2006-42, CVE-2006-2783)\n\nPaul Nickerson noticed that the fix for CVE-2005-0752 (JavaScript\nprivilege escalation on the plugins page) was not sufficient to\nprevent all variants of exploitation. (MFSA 2006-36, CVE-2006-2784)\n\nPaul Nickerson demonstrated that if an attacker could convince a user\nto right-click on a broken image and choose \"View Image\" from the\ncontext menu then he could get JavaScript to run on a site of the\nattacker's choosing. This could be used to steal login cookies or\nother confidential information from the target site. (MFSA 2006-34,\nCVE-2006-2785)\n\nKazuho Oku discovered various ways to perform HTTP response smuggling\nwhen used with certain proxy servers. Due to different interpretation\nof nonstandard HTTP headers in Firefox and the proxy server, a\nmalicious web site can exploit this to send back two responses to one\nrequest. The second response could be used to steal login cookies or\nother sensitive data from another opened web site. (MFSA 2006-33,\nCVE-2006-2786)","is_hidden":false,"release_packages":{"dapper":[{"name":"firefox","version":"1.5.dfsg+1.5.0.4-0ubuntu6.06","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2006-2775","CVE-2006-2776","CVE-2006-2777","CVE-2006-2778","CVE-2006-2779","CVE-2006-2780","CVE-2006-2782","CVE-2006-2783","CVE-2006-2784","CVE-2006-2785","CVE-2006-2786","CVE-2006-2787","CVE-2006-2788"]}]},{"id":"CVE-2006-2781","published":"2006-06-02T19:02:00","updated_at":"2025-07-17T16:38:57.863203+00:00","description":"\nDouble free vulnerability in nsVCard.cpp in Mozilla Thunderbird before\n1.5.0.4 and SeaMonkey before 1.0.2 allows remote attackers to cause a\ndenial of service (hang) and possibly execute arbitrary code via a VCard\nthat contains invalid base64 characters.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-297-1","https://ubuntu.com/security/notices/USN-297-3","https://ubuntu.com/security/notices/USN-323-1","https://www.cve.org/CVERecord?id=CVE-2006-2781"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"mozilla-thunderbird","source":"https://ubuntu.com/security/cve?package=mozilla-thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozilla-thunderbird","debian":"https://tracker.debian.org/pkg/mozilla-thunderbird","statuses":[{"release_codename":"dapper","status":"released","description":"1.5.0.13-0ubuntu0.6.06","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.5.0.13-0ubuntu0.6.10","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.5.0.13-0ubuntu0.7.04","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-323-1","USN-297-1","USN-297-3"],"notices":[{"id":"USN-323-1","title":"mozilla vulnerabilities","summary":"mozilla vulnerabilities","instructions":"After a standard system upgrade you need to restart Mozilla to effect\nthe necessary changes.","references":[],"published":"2006-07-26T02:47:37","description":"Jonas Sicking discovered that under some circumstances persisted XUL\nattributes are associated with the wrong URL. A malicious web site\ncould exploit this to execute arbitrary code with the privileges of\nthe user. (MFSA 2006-35, CVE-2006-2775)\n\nPaul Nickerson discovered that content-defined setters on an object\nprototype were getting called by privileged UI code. It was\ndemonstrated that this could be exploited to run arbitrary web script\nwith full user privileges (MFSA 2006-37, CVE-2006-2776). A similar\nattack was discovered by moz_bug_r_a4 that leveraged SelectionObject\nnotifications that were called in privileged context. (MFSA 2006-43,\nCVE-2006-2777)\n\nMikolaj Habryn discovered a buffer overflow in the crypto.signText()\nfunction. By tricking a user to visit a site with an SSL certificate\nwith specially crafted optional Certificate Authority name\narguments, this could potentially be exploited to execute arbitrary\ncode with the user's privileges. (MFSA 2006-38, CVE-2006-2778)\n\nThe Mozilla developer team discovered several bugs that lead to\ncrashes with memory corruption. These might be exploitable by\nmalicious web sites to execute arbitrary code with the privileges of\nthe user. (MFSA 2006-32, CVE-2006-2779, CVE-2006-2780)\n\nMasatoshi Kimura discovered a memory corruption (double-free) when\nprocessing a large VCard with invalid base64 characters in it. By\nsending a maliciously crafted set of VCards to a user, this could\npotentially be exploited to execute arbitrary code with the user's\nprivileges. (MFSA 2006-40, CVE-2006-2781)\n\nChuck McAuley reported that the fix for CVE-2006-1729 (file stealing\nby changing input type) was not sufficient to prevent all variants of\nexploitation. (MFSA 2006-41, CVE-2006-2782)\n\nMasatoshi Kimura found a way to bypass web input sanitizers which\nfilter out JavaScript. By inserting 'Unicode Byte-order-Mark (BOM)'\ncharacters into the HTML code (e. g. ''), these filters\nmight not recognize the tags anymore; however, Mozilla would still\nexecute them since BOM markers are filtered out before processing the\npage. (MFSA 2006-42, CVE-2006-2783)\n\nPaul Nickerson noticed that the fix for CVE-2005-0752 (JavaScript\nprivilege escalation on the plugins page) was not sufficient to\nprevent all variants of exploitation. (MFSA 2006-36, CVE-2006-2784)\n\nPaul Nickerson demonstrated that if an attacker could convince a user\nto right-click on a broken image and choose \"View Image\" from the\ncontext menu then he could get JavaScript to run on a site of the\nattacker's choosing. This could be used to steal login cookies or\nother confidential information from the target site. (MFSA 2006-34,\nCVE-2006-2785)\n\nKazuho Oku discovered various ways to perform HTTP response smuggling\nwhen used with certain proxy servers. Due to different interpretation\nof nonstandard HTTP headers in Mozilla and the proxy server, a\nmalicious web site can exploit this to send back two responses to one\nrequest. The second response could be used to steal login cookies or\nother sensitive data from another opened web site. (MFSA 2006-33,\nCVE-2006-2786)","is_hidden":false,"release_packages":{"hoary":[{"name":"mozilla-psm","version":"2:1.7.13-0ubuntu05.04.1","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-mailnews","version":"2:1.7.13-0ubuntu05.04.1","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-browser","version":"2:1.7.13-0ubuntu05.04.1","is_source":false,"source_link":"","version_link":""}],"breezy":[{"name":"mozilla-psm","version":"2:1.7.13-0ubuntu5.10.1","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-mailnews","version":"2:1.7.13-0ubuntu5.10.1","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-browser","version":"2:1.7.13-0ubuntu5.10.1","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2006-2775","CVE-2006-2776","CVE-2006-2777","CVE-2006-2778","CVE-2006-2779","CVE-2006-2780","CVE-2006-2781","CVE-2006-2782","CVE-2006-2783","CVE-2006-2784","CVE-2006-2785","CVE-2006-2786","CVE-2006-2787"]},{"id":"USN-297-1","title":"Thunderbird vulnerabilities","summary":"Thunderbird vulnerabilities","instructions":"After a standard system upgrade you need to restart Thunderbird to\neffect the necessary changes.\n\nPlease note that Thunderbird 1.0.8 in Ubuntu 5.10 and Ubuntu 5.04 are\nalso affected by these problems. Updates for these Ubuntu releases\nwill be delayed due to upstream dropping support for this Thunderbird\nversion. We strongly advise that you disable JavaScript to disable the\nattack vectors for most vulnerabilities if you use one of these Ubuntu\nversions.","references":[],"published":"2006-06-14T17:45:48","description":"Jonas Sicking discovered that under some circumstances persisted XUL\nattributes are associated with the wrong URL. A malicious web site\ncould exploit this to execute arbitrary code with the privileges of\nthe user. (MFSA 2006-35, CVE-2006-2775)\n\nPaul Nickerson discovered that content-defined setters on an object\nprototype were getting called by privileged UI code. It was\ndemonstrated that this could be exploited to run arbitrary web script\nwith full user privileges (MFSA 2006-37, CVE-2006-2776).\n\nMikolaj Habryn discovered a buffer overflow in the crypto.signText()\nfunction. By sending an email with malicious JavaScript to an user,\nand that user enabled JavaScript in Thunderbird (which is not the\ndefault and not recommended), this could potentially be exploited to\nexecute arbitrary code with the user's privileges. (MFSA 2006-38,\nCVE-2006-2778)\n\nThe Mozilla developer team discovered several bugs that lead to\ncrashes with memory corruption. These might be exploitable by\nmalicious web sites to execute arbitrary code with the privileges of\nthe user. (MFSA 2006-32, CVE-2006-2779, CVE-2006-2780)\n\nMasatoshi Kimura discovered a memory corruption (double-free) when\nprocessing a large VCard with invalid base64 characters in it. By\nsending a maliciously crafted set of VCards to a user, this could\npotentially be exploited to execute arbitrary code with the user's\nprivileges. (MFSA 2006-40, CVE-2006-2781)\n\nMasatoshi Kimura found a way to bypass web input sanitizers which\nfilter out JavaScript. By inserting 'Unicode Byte-order-Mark (BOM)'\ncharacters into the HTML code (e. g. ''), these filters\nmight not recognize the tags anymore; however, Thunderbird would still\nexecute them since BOM markers are filtered out before processing a\nmail containing JavaScript. (MFSA 2006-42, CVE-2006-2783)\n\nKazuho Oku discovered various ways to perform HTTP response smuggling\nwhen used with certain proxy servers. Due to different interpretation\nof nonstandard HTTP headers in Thunderbird and the proxy server, a\nmalicious HTML email can exploit this to send back two responses to one\nrequest. The second response could be used to steal login cookies or\nother sensitive data from another opened web site. (MFSA 2006-33,\nCVE-2006-2786)\n\nIt was discovered that JavaScript run via EvalInSandbox() can escape\nthe sandbox. Malicious scripts received in emails containing\nJavaScript could use these privileges to execute arbitrary code with\nthe user's privileges. (MFSA 2006-31, CVE-2006-2787)\n\nThe \"enigmail\" plugin has been updated to work with the new\nThunderbird version.","is_hidden":false,"release_packages":{"dapper":[{"name":"mozilla-thunderbird","version":"1.5.0.4-0ubuntu6.06","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-thunderbird-enigmail","version":"2:0.94-0ubuntu4.1","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2006-2775","CVE-2006-2776","CVE-2006-2778","CVE-2006-2779","CVE-2006-2780","CVE-2006-2781","CVE-2006-2783","CVE-2006-2786","CVE-2006-2787"]},{"id":"USN-297-3","title":"Thunderbird vulnerabilities","summary":"Thunderbird vulnerabilities","instructions":"After a standard system upgrade you need to restart Thunderbird to\neffect the necessary changes.","references":[],"published":"2006-07-26T17:25:23","description":"USN-297-1 fixed several vulnerabilities in Thunderbird for the Ubuntu\n6.06 LTS release. This update provides the corresponding fixes for\nUbuntu 5.04 and Ubuntu 5.10.\n\nFor reference, these are the details of the original USN:\n\n Jonas Sicking discovered that under some circumstances persisted XUL\n attributes are associated with the wrong URL. A malicious web site\n could exploit this to execute arbitrary code with the privileges of\n the user. (MFSA 2006-35, CVE-2006-2775)\n\n Paul Nickerson discovered that content-defined setters on an object\n prototype were getting called by privileged UI code. It was\n demonstrated that this could be exploited to run arbitrary web\n script with full user privileges (MFSA 2006-37, CVE-2006-2776).\n\n Mikolaj Habryn discovered a buffer overflow in the crypto.signText()\n function. By sending an email with malicious JavaScript to an user,\n and that user enabled JavaScript in Thunderbird (which is not the\n default and not recommended), this could potentially be exploited to\n execute arbitrary code with the user's privileges. (MFSA 2006-38,\n CVE-2006-2778)\n\n The Mozilla developer team discovered several bugs that lead to\n crashes with memory corruption. These might be exploitable by\n malicious web sites to execute arbitrary code with the privileges of\n the user. (MFSA 2006-32, CVE-2006-2779, CVE-2006-2780)\n\n Masatoshi Kimura discovered a memory corruption (double-free) when\n processing a large VCard with invalid base64 characters in it. By\n sending a maliciously crafted set of VCards to a user, this could\n potentially be exploited to execute arbitrary code with the user's\n privileges. (MFSA 2006-40, CVE-2006-2781)\n\n Masatoshi Kimura found a way to bypass web input sanitizers which\n filter out JavaScript. By inserting 'Unicode Byte-order-Mark (BOM)'\n characters into the HTML code (e. g. ''), these filters\n might not recognize the tags anymore; however, Thunderbird would\n still execute them since BOM markers are filtered out before\n processing a mail containing JavaScript. (MFSA 2006-42,\n CVE-2006-2783)\n\n Kazuho Oku discovered various ways to perform HTTP response\n smuggling when used with certain proxy servers. Due to different\n interpretation of nonstandard HTTP headers in Thunderbird and the\n proxy server, a malicious HTML email can exploit this to send back\n two responses to one request. The second response could be used to\n steal login cookies or other sensitive data from another opened web\n site. (MFSA 2006-33, CVE-2006-2786)\n\n It was discovered that JavaScript run via EvalInSandbox() can escape\n the sandbox. Malicious scripts received in emails containing\n JavaScript could use these privileges to execute arbitrary code with\n the user's privileges. (MFSA 2006-31, CVE-2006-2787)","is_hidden":false,"release_packages":{"hoary":[{"name":"mozilla-thunderbird","version":"1.0.8-0ubuntu05.04.1","is_source":false,"source_link":"","version_link":""}],"breezy":[{"name":"mozilla-thunderbird","version":"1.0.8-0ubuntu05.10.2","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2006-2775","CVE-2006-2776","CVE-2006-2778","CVE-2006-2779","CVE-2006-2780","CVE-2006-2781","CVE-2006-2783","CVE-2006-2784","CVE-2006-2787"]}]},{"id":"CVE-2006-2780","published":"2006-06-02T19:02:00","updated_at":"2025-07-17T16:38:57.863203+00:00","description":"\nInteger overflow in Mozilla Firefox and Thunderbird before 1.5.0.4 allows\nremote attackers to cause a denial of service (crash) and possibly execute\narbitrary code via \"jsstr tagify,\" which leads to memory corruption.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-296-1","https://ubuntu.com/security/notices/USN-296-2","https://ubuntu.com/security/notices/USN-297-1","https://ubuntu.com/security/notices/USN-297-3","https://ubuntu.com/security/notices/USN-323-1","https://www.cve.org/CVERecord?id=CVE-2006-2780"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"dapper","status":"released","description":"1.5.dfsg+1.5.0.13~prepatch070731-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"edgy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"firefox-granparadiso","source":"https://ubuntu.com/security/cve?package=firefox-granparadiso","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox-granparadiso","debian":"https://tracker.debian.org/pkg/firefox-granparadiso","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"lightning-sunbird","source":"https://ubuntu.com/security/cve?package=lightning-sunbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=lightning-sunbird","debian":"https://tracker.debian.org/pkg/lightning-sunbird","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"midbrowser","source":"https://ubuntu.com/security/cve?package=midbrowser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=midbrowser","debian":"https://tracker.debian.org/pkg/midbrowser","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"feisty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mozilla-thunderbird","source":"https://ubuntu.com/security/cve?package=mozilla-thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozilla-thunderbird","debian":"https://tracker.debian.org/pkg/mozilla-thunderbird","statuses":[{"release_codename":"dapper","status":"released","description":"1.5.0.13-0ubuntu0.6.06","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.5.0.13-0ubuntu0.6.10","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.5.0.13-0ubuntu0.7.04","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"xulrunner","source":"https://ubuntu.com/security/cve?package=xulrunner","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xulrunner","debian":"https://tracker.debian.org/pkg/xulrunner","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"edgy","status":"released","description":"1.8.0.5-4.2","component":null,"pocket":"security"},{"release_codename":"feisty","status":"released","description":"1.8.0.5-4.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-323-1","USN-297-1","USN-297-3","USN-296-2","USN-296-1"],"notices":[{"id":"USN-323-1","title":"mozilla vulnerabilities","summary":"mozilla vulnerabilities","instructions":"After a standard system upgrade you need to restart Mozilla to effect\nthe necessary changes.","references":[],"published":"2006-07-26T02:47:37","description":"Jonas Sicking discovered that under some circumstances persisted XUL\nattributes are associated with the wrong URL. A malicious web site\ncould exploit this to execute arbitrary code with the privileges of\nthe user. (MFSA 2006-35, CVE-2006-2775)\n\nPaul Nickerson discovered that content-defined setters on an object\nprototype were getting called by privileged UI code. It was\ndemonstrated that this could be exploited to run arbitrary web script\nwith full user privileges (MFSA 2006-37, CVE-2006-2776). A similar\nattack was discovered by moz_bug_r_a4 that leveraged SelectionObject\nnotifications that were called in privileged context. (MFSA 2006-43,\nCVE-2006-2777)\n\nMikolaj Habryn discovered a buffer overflow in the crypto.signText()\nfunction. By tricking a user to visit a site with an SSL certificate\nwith specially crafted optional Certificate Authority name\narguments, this could potentially be exploited to execute arbitrary\ncode with the user's privileges. (MFSA 2006-38, CVE-2006-2778)\n\nThe Mozilla developer team discovered several bugs that lead to\ncrashes with memory corruption. These might be exploitable by\nmalicious web sites to execute arbitrary code with the privileges of\nthe user. (MFSA 2006-32, CVE-2006-2779, CVE-2006-2780)\n\nMasatoshi Kimura discovered a memory corruption (double-free) when\nprocessing a large VCard with invalid base64 characters in it. By\nsending a maliciously crafted set of VCards to a user, this could\npotentially be exploited to execute arbitrary code with the user's\nprivileges. (MFSA 2006-40, CVE-2006-2781)\n\nChuck McAuley reported that the fix for CVE-2006-1729 (file stealing\nby changing input type) was not sufficient to prevent all variants of\nexploitation. (MFSA 2006-41, CVE-2006-2782)\n\nMasatoshi Kimura found a way to bypass web input sanitizers which\nfilter out JavaScript. By inserting 'Unicode Byte-order-Mark (BOM)'\ncharacters into the HTML code (e. g. ''), these filters\nmight not recognize the tags anymore; however, Mozilla would still\nexecute them since BOM markers are filtered out before processing the\npage. (MFSA 2006-42, CVE-2006-2783)\n\nPaul Nickerson noticed that the fix for CVE-2005-0752 (JavaScript\nprivilege escalation on the plugins page) was not sufficient to\nprevent all variants of exploitation. (MFSA 2006-36, CVE-2006-2784)\n\nPaul Nickerson demonstrated that if an attacker could convince a user\nto right-click on a broken image and choose \"View Image\" from the\ncontext menu then he could get JavaScript to run on a site of the\nattacker's choosing. This could be used to steal login cookies or\nother confidential information from the target site. (MFSA 2006-34,\nCVE-2006-2785)\n\nKazuho Oku discovered various ways to perform HTTP response smuggling\nwhen used with certain proxy servers. Due to different interpretation\nof nonstandard HTTP headers in Mozilla and the proxy server, a\nmalicious web site can exploit this to send back two responses to one\nrequest. The second response could be used to steal login cookies or\nother sensitive data from another opened web site. (MFSA 2006-33,\nCVE-2006-2786)","is_hidden":false,"release_packages":{"hoary":[{"name":"mozilla-psm","version":"2:1.7.13-0ubuntu05.04.1","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-mailnews","version":"2:1.7.13-0ubuntu05.04.1","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-browser","version":"2:1.7.13-0ubuntu05.04.1","is_source":false,"source_link":"","version_link":""}],"breezy":[{"name":"mozilla-psm","version":"2:1.7.13-0ubuntu5.10.1","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-mailnews","version":"2:1.7.13-0ubuntu5.10.1","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-browser","version":"2:1.7.13-0ubuntu5.10.1","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2006-2775","CVE-2006-2776","CVE-2006-2777","CVE-2006-2778","CVE-2006-2779","CVE-2006-2780","CVE-2006-2781","CVE-2006-2782","CVE-2006-2783","CVE-2006-2784","CVE-2006-2785","CVE-2006-2786","CVE-2006-2787"]},{"id":"USN-297-1","title":"Thunderbird vulnerabilities","summary":"Thunderbird vulnerabilities","instructions":"After a standard system upgrade you need to restart Thunderbird to\neffect the necessary changes.\n\nPlease note that Thunderbird 1.0.8 in Ubuntu 5.10 and Ubuntu 5.04 are\nalso affected by these problems. Updates for these Ubuntu releases\nwill be delayed due to upstream dropping support for this Thunderbird\nversion. We strongly advise that you disable JavaScript to disable the\nattack vectors for most vulnerabilities if you use one of these Ubuntu\nversions.","references":[],"published":"2006-06-14T17:45:48","description":"Jonas Sicking discovered that under some circumstances persisted XUL\nattributes are associated with the wrong URL. A malicious web site\ncould exploit this to execute arbitrary code with the privileges of\nthe user. (MFSA 2006-35, CVE-2006-2775)\n\nPaul Nickerson discovered that content-defined setters on an object\nprototype were getting called by privileged UI code. It was\ndemonstrated that this could be exploited to run arbitrary web script\nwith full user privileges (MFSA 2006-37, CVE-2006-2776).\n\nMikolaj Habryn discovered a buffer overflow in the crypto.signText()\nfunction. By sending an email with malicious JavaScript to an user,\nand that user enabled JavaScript in Thunderbird (which is not the\ndefault and not recommended), this could potentially be exploited to\nexecute arbitrary code with the user's privileges. (MFSA 2006-38,\nCVE-2006-2778)\n\nThe Mozilla developer team discovered several bugs that lead to\ncrashes with memory corruption. These might be exploitable by\nmalicious web sites to execute arbitrary code with the privileges of\nthe user. (MFSA 2006-32, CVE-2006-2779, CVE-2006-2780)\n\nMasatoshi Kimura discovered a memory corruption (double-free) when\nprocessing a large VCard with invalid base64 characters in it. By\nsending a maliciously crafted set of VCards to a user, this could\npotentially be exploited to execute arbitrary code with the user's\nprivileges. (MFSA 2006-40, CVE-2006-2781)\n\nMasatoshi Kimura found a way to bypass web input sanitizers which\nfilter out JavaScript. By inserting 'Unicode Byte-order-Mark (BOM)'\ncharacters into the HTML code (e. g. ''), these filters\nmight not recognize the tags anymore; however, Thunderbird would still\nexecute them since BOM markers are filtered out before processing a\nmail containing JavaScript. (MFSA 2006-42, CVE-2006-2783)\n\nKazuho Oku discovered various ways to perform HTTP response smuggling\nwhen used with certain proxy servers. Due to different interpretation\nof nonstandard HTTP headers in Thunderbird and the proxy server, a\nmalicious HTML email can exploit this to send back two responses to one\nrequest. The second response could be used to steal login cookies or\nother sensitive data from another opened web site. (MFSA 2006-33,\nCVE-2006-2786)\n\nIt was discovered that JavaScript run via EvalInSandbox() can escape\nthe sandbox. Malicious scripts received in emails containing\nJavaScript could use these privileges to execute arbitrary code with\nthe user's privileges. (MFSA 2006-31, CVE-2006-2787)\n\nThe \"enigmail\" plugin has been updated to work with the new\nThunderbird version.","is_hidden":false,"release_packages":{"dapper":[{"name":"mozilla-thunderbird","version":"1.5.0.4-0ubuntu6.06","is_source":false,"source_link":"","version_link":""},{"name":"mozilla-thunderbird-enigmail","version":"2:0.94-0ubuntu4.1","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2006-2775","CVE-2006-2776","CVE-2006-2778","CVE-2006-2779","CVE-2006-2780","CVE-2006-2781","CVE-2006-2783","CVE-2006-2786","CVE-2006-2787"]},{"id":"USN-297-3","title":"Thunderbird vulnerabilities","summary":"Thunderbird vulnerabilities","instructions":"After a standard system upgrade you need to restart Thunderbird to\neffect the necessary changes.","references":[],"published":"2006-07-26T17:25:23","description":"USN-297-1 fixed several vulnerabilities in Thunderbird for the Ubuntu\n6.06 LTS release. This update provides the corresponding fixes for\nUbuntu 5.04 and Ubuntu 5.10.\n\nFor reference, these are the details of the original USN:\n\n Jonas Sicking discovered that under some circumstances persisted XUL\n attributes are associated with the wrong URL. A malicious web site\n could exploit this to execute arbitrary code with the privileges of\n the user. (MFSA 2006-35, CVE-2006-2775)\n\n Paul Nickerson discovered that content-defined setters on an object\n prototype were getting called by privileged UI code. It was\n demonstrated that this could be exploited to run arbitrary web\n script with full user privileges (MFSA 2006-37, CVE-2006-2776).\n\n Mikolaj Habryn discovered a buffer overflow in the crypto.signText()\n function. By sending an email with malicious JavaScript to an user,\n and that user enabled JavaScript in Thunderbird (which is not the\n default and not recommended), this could potentially be exploited to\n execute arbitrary code with the user's privileges. (MFSA 2006-38,\n CVE-2006-2778)\n\n The Mozilla developer team discovered several bugs that lead to\n crashes with memory corruption. These might be exploitable by\n malicious web sites to execute arbitrary code with the privileges of\n the user. (MFSA 2006-32, CVE-2006-2779, CVE-2006-2780)\n\n Masatoshi Kimura discovered a memory corruption (double-free) when\n processing a large VCard with invalid base64 characters in it. By\n sending a maliciously crafted set of VCards to a user, this could\n potentially be exploited to execute arbitrary code with the user's\n privileges. (MFSA 2006-40, CVE-2006-2781)\n\n Masatoshi Kimura found a way to bypass web input sanitizers which\n filter out JavaScript. By inserting 'Unicode Byte-order-Mark (BOM)'\n characters into the HTML code (e. g. ''), these filters\n might not recognize the tags anymore; however, Thunderbird would\n still execute them since BOM markers are filtered out before\n processing a mail containing JavaScript. (MFSA 2006-42,\n CVE-2006-2783)\n\n Kazuho Oku discovered various ways to perform HTTP response\n smuggling when used with certain proxy servers. Due to different\n interpretation of nonstandard HTTP headers in Thunderbird and the\n proxy server, a malicious HTML email can exploit this to send back\n two responses to one request. The second response could be used to\n steal login cookies or other sensitive data from another opened web\n site. (MFSA 2006-33, CVE-2006-2786)\n\n It was discovered that JavaScript run via EvalInSandbox() can escape\n the sandbox. Malicious scripts received in emails containing\n JavaScript could use these privileges to execute arbitrary code with\n the user's privileges. (MFSA 2006-31, CVE-2006-2787)","is_hidden":false,"release_packages":{"hoary":[{"name":"mozilla-thunderbird","version":"1.0.8-0ubuntu05.04.1","is_source":false,"source_link":"","version_link":""}],"breezy":[{"name":"mozilla-thunderbird","version":"1.0.8-0ubuntu05.10.2","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2006-2775","CVE-2006-2776","CVE-2006-2778","CVE-2006-2779","CVE-2006-2780","CVE-2006-2781","CVE-2006-2783","CVE-2006-2784","CVE-2006-2787"]},{"id":"USN-296-2","title":"Firefox vulnerabilities","summary":"Firefox vulnerabilities","instructions":"After a standard system upgrade you need to restart Firefox to effect\nthe necessary changes.","references":[],"published":"2006-07-25T17:49:50","description":"USN-296-1 fixed several vulnerabilities in Firefox for the Ubuntu 6.06\nLTS release. This update provides the corresponding fixes for Ubuntu\n5.04 and Ubuntu 5.10.\n\nFor reference, these are the details of the original USN:\n\n Jonas Sicking discovered that under some circumstances persisted XUL\n attributes are associated with the wrong URL. A malicious web site\n could exploit this to execute arbitrary code with the privileges of\n the user. (MFSA 2006-35, CVE-2006-2775)\n \n Paul Nickerson discovered that content-defined setters on an object\n prototype were getting called by privileged UI code. It was\n demonstrated that this could be exploited to run arbitrary web script\n with full user privileges (MFSA 2006-37, CVE-2006-2776). A similar\n attack was discovered by moz_bug_r_a4 that leveraged SelectionObject\n notifications that were called in privileged context. (MFSA 2006-43,\n CVE-2006-2777)\n \n Mikolaj Habryn discovered a buffer overflow in the crypto.signText()\n function. By tricking a user to visit a site with an SSL certificate\n with specially crafted optional Certificate Authority name\n arguments, this could potentially be exploited to execute arbitrary\n code with the user's privileges. (MFSA 2006-38, CVE-2006-2778)\n \n The Mozilla developer team discovered several bugs that lead to\n crashes with memory corruption. These might be exploitable by\n malicious web sites to execute arbitrary code with the privileges of\n the user. (MFSA 2006-32, CVE-2006-2779, CVE-2006-2780, CVE-2006-2788)\n \n Chuck McAuley reported that the fix for CVE-2006-1729 (file stealing\n by changing input type) was not sufficient to prevent all variants of\n exploitation. (MFSA 2006-41, CVE-2006-2782)\n \n Masatoshi Kimura found a way to bypass web input sanitizers which\n filter out JavaScript. By inserting 'Unicode Byte-order-Mark (BOM)'\n characters into the HTML code (e. g. ''), these filters\n might not recognize the tags anymore; however, Firefox would still\n execute them since BOM markers are filtered out before processing the\n page. (MFSA 2006-42, CVE-2006-2783)\n \n Paul Nickerson noticed that the fix for CVE-2005-0752 (JavaScript\n privilege escalation on the plugins page) was not sufficient to\n prevent all variants of exploitation. (MFSA 2006-36, CVE-2006-2784)\n \n Paul Nickerson demonstrated that if an attacker could convince a user\n to right-click on a broken image and choose \"View Image\" from the\n context menu then he could get JavaScript to run on a site of the\n attacker's choosing. This could be used to steal login cookies or\n other confidential information from the target site. (MFSA 2006-34,\n CVE-2006-2785)\n \n Kazuho Oku discovered various ways to perform HTTP response smuggling\n when used with certain proxy servers. Due to different interpretation\n of nonstandard HTTP headers in Firefox and the proxy server, a\n malicious web site can exploit this to send back two responses to one\n request. The second response could be used to steal login cookies or\n other sensitive data from another opened web site. (MFSA 2006-33,\n CVE-2006-2786)","is_hidden":false,"release_packages":{"hoary":[{"name":"mozilla-firefox","version":"1.0.8-0ubuntu5.04.1","is_source":false,"source_link":"","version_link":""}],"breezy":[{"name":"firefox","version":"1.0.8-0ubuntu5.10.1","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2006-2775","CVE-2006-2776","CVE-2006-2777","CVE-2006-2778","CVE-2006-2779","CVE-2006-2780","CVE-2006-2782","CVE-2006-2783","CVE-2006-2784","CVE-2006-2785","CVE-2006-2786","CVE-2006-2787"]},{"id":"USN-296-1","title":"firefox vulnerabilities","summary":"firefox vulnerabilities","instructions":"After a standard system upgrade you need to restart Firefox to effect\nthe necessary changes.\n\nPlease note that Firefox 1.0.8 in Ubuntu 5.10 and Ubuntu 5.04 are also\naffected by these problems. Updates for these Ubuntu releases will be\ndelayed due to upstream dropping support for this Firefox version. We\nstrongly advise that you disable JavaScript to disable the attack\nvectors for most vulnerabilities if you use one of these Ubuntu\nversions.","references":[],"published":"2006-06-09T22:13:38","description":"Jonas Sicking discovered that under some circumstances persisted XUL\nattributes are associated with the wrong URL. A malicious web site\ncould exploit this to execute arbitrary code with the privileges of\nthe user. (MFSA 2006-35, CVE-2006-2775)\n\nPaul Nickerson discovered that content-defined setters on an object\nprototype were getting called by privileged UI code. It was\ndemonstrated that this could be exploited to run arbitrary web script\nwith full user privileges (MFSA 2006-37, CVE-2006-2776). A similar\nattack was discovered by moz_bug_r_a4 that leveraged SelectionObject\nnotifications that were called in privileged context. (MFSA 2006-43,\nCVE-2006-2777)\n\nMikolaj Habryn discovered a buffer overflow in the crypto.signText()\nfunction. By tricking a user to visit a site with an SSL certificate\nwith specially crafted optional Certificate Authority name\narguments, this could potentially be exploited to execute arbitrary\ncode with the user's privileges. (MFSA 2006-38, CVE-2006-2778)\n\nThe Mozilla developer team discovered several bugs that lead to\ncrashes with memory corruption. These might be exploitable by\nmalicious web sites to execute arbitrary code with the privileges of\nthe user. (MFSA 2006-32, CVE-2006-2779, CVE-2006-2780, CVE-2006-2788)\n\nChuck McAuley reported that the fix for CVE-2006-1729 (file stealing\nby changing input type) was not sufficient to prevent all variants of\nexploitation. (MFSA 2006-41, CVE-2006-2782)\n\nMasatoshi Kimura found a way to bypass web input sanitizers which\nfilter out JavaScript. By inserting 'Unicode Byte-order-Mark (BOM)'\ncharacters into the HTML code (e. g. ''), these filters\nmight not recognize the tags anymore; however, Firefox would still\nexecute them since BOM markers are filtered out before processing the\npage. (MFSA 2006-42, CVE-2006-2783)\n\nPaul Nickerson noticed that the fix for CVE-2005-0752 (JavaScript\nprivilege escalation on the plugins page) was not sufficient to\nprevent all variants of exploitation. (MFSA 2006-36, CVE-2006-2784)\n\nPaul Nickerson demonstrated that if an attacker could convince a user\nto right-click on a broken image and choose \"View Image\" from the\ncontext menu then he could get JavaScript to run on a site of the\nattacker's choosing. This could be used to steal login cookies or\nother confidential information from the target site. (MFSA 2006-34,\nCVE-2006-2785)\n\nKazuho Oku discovered various ways to perform HTTP response smuggling\nwhen used with certain proxy servers. Due to different interpretation\nof nonstandard HTTP headers in Firefox and the proxy server, a\nmalicious web site can exploit this to send back two responses to one\nrequest. The second response could be used to steal login cookies or\nother sensitive data from another opened web site. (MFSA 2006-33,\nCVE-2006-2786)","is_hidden":false,"release_packages":{"dapper":[{"name":"firefox","version":"1.5.dfsg+1.5.0.4-0ubuntu6.06","is_source":false,"source_link":"","version_link":""}]},"type":"USN","cves_ids":["CVE-2006-2775","CVE-2006-2776","CVE-2006-2777","CVE-2006-2778","CVE-2006-2779","CVE-2006-2780","CVE-2006-2782","CVE-2006-2783","CVE-2006-2784","CVE-2006-2785","CVE-2006-2786","CVE-2006-2787","CVE-2006-2788"]}]},{"id":"CVE-2006-2779","published":"2006-06-02T19:02:00","updated_at":"2025-07-17T16:38:56.335100+00:00","description":"\nMozilla Firefox and Thunderbird before 1.5.0.4 allow remote attackers to\ncause a denial of service (crash) and possibly execute arbitrary code via\n(1) nested