Vulnerability Database

289,689

Total vulnerabilities in the database

CVE-2006-2778

The crypto.signText function in Mozilla Firefox and Thunderbird before 1.5.0.4 allows remote attackers to execute arbitrary code via certain optional Certificate Authority name arguments, which causes an invalid array index and triggers a buffer overflow.

  • Published: Jun 2, 2006
  • Updated: Apr 13, 2023
  • CVE: CVE-2006-2778
  • Severity: Medium
  • Exploit:

CVSS v2:

  • Severity: Medium
  • Score: 5
  • AV:N/AC:L/Au:N/C:N/I:P/A:N

No CWE or OWASP classifications available.

Software From Fixed in
mozilla / firefox - 1.5.0.3.x
mozilla / thunderbird - 1.5.0.3.x