{"api_version":"1","generated_at":"2026-07-23T07:49:43+00:00","cve":"CVE-2006-5330","urls":{"html":"https://cve.report/CVE-2006-5330","api":"https://cve.report/api/cve/CVE-2006-5330.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-5330","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-5330"},"summary":{"title":"CVE-2006-5330","description":"CRLF injection vulnerability in Adobe Flash Player plugin 9.0.16 and earlier for Windows, 7.0.63 and earlier for Linux, 7.x before 7.0 r67 for Solaris, and before 9.0.28.0 for Mac OS X, allows remote attackers to modify HTTP headers of client requests and conduct HTTP Request Splitting attacks via CRLF sequences in arguments to the ActionScript functions (1) XML.addRequestHeader and (2) XML.contentType.  NOTE: the flexibility of the attack varies depending on the type of web browser being used.","state":"PUBLISHED","assigner":"mitre","published_at":"2006-10-17 21:07:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-79","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.vupen.com/english/advisories/2007/1999","name":"http://www.vupen.com/english/advisories/2007/1999","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/20592","name":"http://www.securityfocus.com/bid/20592","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Adobe Flash Player Plugin HTTP Header Injection Weakness","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.adobe.com/support/security/bulletins/apsb06-18.html","name":"http://www.adobe.com/support/security/bulletins/apsb06-18.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Adobe - Security Advisories : Update available for HTTP header injection vulnerabilities in Adobe Flash Player","mime":"text/xml","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2006/4094","name":"http://www.vupen.com/english/advisories/2006/4094","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html","name":"http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"APPLE-SA-2007-03-13 Mac OS X v10.4.9 and Security Update 2007-003","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securitytracker.com/id?1017078","name":"http://securitytracker.com/id?1017078","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityTracker.com Archives - Adobe Flash Player Plugin Lets Remote Users Injection Arbitrary HTTP Header Data","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2007/0930","name":"http://www.vupen.com/english/advisories/2007/0930","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail - OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/29863","name":"http://www.osvdb.org/29863","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.rapid7.com/advisories/R7-0026.jsp","name":"http://www.rapid7.com/advisories/R7-0026.jsp","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Rapid7 Security Advisory R7-0026: HTTP Header Injection Vulnerabilities in the Flash Player Plugin","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://www.us-cert.gov/cas/techalerts/TA07-072A.html","name":"http://www.us-cert.gov/cas/techalerts/TA07-072A.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["US Government Resource"],"title":"US-CERT Technical Cyber Security Alert TA07-072A -- Apple Updates for Multiple Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11405","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11405","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/29634","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/29634","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/25467","name":"http://secunia.com/advisories/25467","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Sun Solaris update for Adobe Flash Player - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.redhat.com/support/errata/RHSA-2007-0009.html","name":"http://www.redhat.com/support/errata/RHSA-2007-0009.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"rhn.redhat.com | Red Hat Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/24479","name":"http://secunia.com/advisories/24479","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Mac OS X Security Update Fixes Multiple Vulnerabilities - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securityreason.com/securityalert/1737","name":"http://securityreason.com/securityalert/1737","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityReason - HTTP Header Injection Vulnerabilities in the Flash Player Plugin","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://docs.info.apple.com/article.html?artnum=305214","name":"http://docs.info.apple.com/article.html?artnum=305214","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"About the security content of Mac OS X 10.4.9 and Security Update 2007-003","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://secunia.com/advisories/23581","name":"http://secunia.com/advisories/23581","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Red Hat update for flash-plugin - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://sunsolve.sun.com/search/document.do?assetkey=1-26-102932-1","name":"http://sunsolve.sun.com/search/document.do?assetkey=1-26-102932-1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"#102932: Security Vulnerability in Adobe Flash Player May Allow Unauthorized Header Injection into HTTP Requests","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/448997/100/0/threaded","name":"http://www.securityfocus.com/archive/1/448997/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/22467","name":"http://secunia.com/advisories/22467","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Adobe Flash Player CRLF Injection Vulnerabilities - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.suse.com/archive/suse-security-announce/2006-Dec/0006.html","name":"http://lists.suse.com/archive/suse-security-announce/2006-Dec/0006.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SuSE Security announcements: [suse-security-announce] SUSE Security Announcement: flash-player CRLF injection (SUSE-SA:2006:077)","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://www.adobe.com/support/security/advisories/apsa06-01.html","name":"http://www.adobe.com/support/security/advisories/apsa06-01.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Adobe - Security Advisories : HTTP header injection vulnerabilities in Adobe Flash Player","mime":"text/xml","httpstatus":"404","archivestatus":"200"},{"url":"http://secunia.com/advisories/23324","name":"http://secunia.com/advisories/23324","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"SUSE update for flash-player - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-5330","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-5330","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"5330","vulnerable":"1","versionEndIncluding":"7.0.63","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"adobe","cpe5":"flash_player","cpe6":"*","cpe7":"*","cpe8":"linux","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"5330","vulnerable":"1","versionEndIncluding":"7.0_r67","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"adobe","cpe5":"flash_player","cpe6":"*","cpe7":"*","cpe8":"solaris","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"5330","vulnerable":"1","versionEndIncluding":"9.0.16","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"adobe","cpe5":"flash_player","cpe6":"*","cpe7":"*","cpe8":"windows","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"5330","vulnerable":"1","versionEndIncluding":"9.0.28.0","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"adobe","cpe5":"flash_player","cpe6":"*","cpe7":"*","cpe8":"mac_os_x","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T19:48:30.288Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.adobe.com/support/security/advisories/apsa06-01.html"},{"name":"TA07-072A","tags":["third-party-advisory","x_refsource_CERT","x_transferred"],"url":"http://www.us-cert.gov/cas/techalerts/TA07-072A.html"},{"name":"102932","tags":["vendor-advisory","x_refsource_SUNALERT","x_transferred"],"url":"http://sunsolve.sun.com/search/document.do?assetkey=1-26-102932-1"},{"name":"22467","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/22467"},{"name":"APPLE-SA-2007-03-13","tags":["vendor-advisory","x_refsource_APPLE","x_transferred"],"url":"http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html"},{"name":"RHSA-2007:0009","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2007-0009.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://docs.info.apple.com/article.html?artnum=305214"},{"name":"23324","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/23324"},{"name":"flashplayer-multiple-xsrf(29634)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/29634"},{"name":"SUSE-SA:2006:077","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.suse.com/archive/suse-security-announce/2006-Dec/0006.html"},{"name":"oval:org.mitre.oval:def:11405","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11405"},{"name":"25467","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/25467"},{"name":"ADV-2006-4094","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2006/4094"},{"name":"29863","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/29863"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.adobe.com/support/security/bulletins/apsb06-18.html"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.rapid7.com/advisories/R7-0026.jsp"},{"name":"20592","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/20592"},{"name":"ADV-2007-0930","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2007/0930"},{"name":"1737","tags":["third-party-advisory","x_refsource_SREASON","x_transferred"],"url":"http://securityreason.com/securityalert/1737"},{"name":"ADV-2007-1999","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2007/1999"},{"name":"23581","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/23581"},{"name":"20061017 Rapid7 Advisory R7-0026: HTTP Header Injection Vulnerabilities in the Flash Player Plugin","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/448997/100/0/threaded"},{"name":"1017078","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1017078"},{"name":"24479","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/24479"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2006-10-17T00:00:00.000Z","descriptions":[{"lang":"en","value":"CRLF injection vulnerability in Adobe Flash Player plugin 9.0.16 and earlier for Windows, 7.0.63 and earlier for Linux, 7.x before 7.0 r67 for Solaris, and before 9.0.28.0 for Mac OS X, allows remote attackers to modify HTTP headers of client requests and conduct HTTP Request Splitting attacks via CRLF sequences in arguments to the ActionScript functions (1) XML.addRequestHeader and (2) XML.contentType.  NOTE: the flexibility of the attack varies depending on the type of web browser being used."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-17T20:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"http://www.adobe.com/support/security/advisories/apsa06-01.html"},{"name":"TA07-072A","tags":["third-party-advisory","x_refsource_CERT"],"url":"http://www.us-cert.gov/cas/techalerts/TA07-072A.html"},{"name":"102932","tags":["vendor-advisory","x_refsource_SUNALERT"],"url":"http://sunsolve.sun.com/search/document.do?assetkey=1-26-102932-1"},{"name":"22467","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/22467"},{"name":"APPLE-SA-2007-03-13","tags":["vendor-advisory","x_refsource_APPLE"],"url":"http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html"},{"name":"RHSA-2007:0009","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2007-0009.html"},{"tags":["x_refsource_CONFIRM"],"url":"http://docs.info.apple.com/article.html?artnum=305214"},{"name":"23324","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/23324"},{"name":"flashplayer-multiple-xsrf(29634)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/29634"},{"name":"SUSE-SA:2006:077","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.suse.com/archive/suse-security-announce/2006-Dec/0006.html"},{"name":"oval:org.mitre.oval:def:11405","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11405"},{"name":"25467","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/25467"},{"name":"ADV-2006-4094","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2006/4094"},{"name":"29863","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/29863"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.adobe.com/support/security/bulletins/apsb06-18.html"},{"tags":["x_refsource_MISC"],"url":"http://www.rapid7.com/advisories/R7-0026.jsp"},{"name":"20592","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/20592"},{"name":"ADV-2007-0930","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2007/0930"},{"name":"1737","tags":["third-party-advisory","x_refsource_SREASON"],"url":"http://securityreason.com/securityalert/1737"},{"name":"ADV-2007-1999","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2007/1999"},{"name":"23581","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/23581"},{"name":"20061017 Rapid7 Advisory R7-0026: HTTP Header Injection Vulnerabilities in the Flash Player Plugin","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/448997/100/0/threaded"},{"name":"1017078","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1017078"},{"name":"24479","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/24479"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2006-5330","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"CRLF injection vulnerability in Adobe Flash Player plugin 9.0.16 and earlier for Windows, 7.0.63 and earlier for Linux, 7.x before 7.0 r67 for Solaris, and before 9.0.28.0 for Mac OS X, allows remote attackers to modify HTTP headers of client requests and conduct HTTP Request Splitting attacks via CRLF sequences in arguments to the ActionScript functions (1) XML.addRequestHeader and (2) XML.contentType.  NOTE: the flexibility of the attack varies depending on the type of web browser being used."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://www.adobe.com/support/security/advisories/apsa06-01.html","refsource":"CONFIRM","url":"http://www.adobe.com/support/security/advisories/apsa06-01.html"},{"name":"TA07-072A","refsource":"CERT","url":"http://www.us-cert.gov/cas/techalerts/TA07-072A.html"},{"name":"102932","refsource":"SUNALERT","url":"http://sunsolve.sun.com/search/document.do?assetkey=1-26-102932-1"},{"name":"22467","refsource":"SECUNIA","url":"http://secunia.com/advisories/22467"},{"name":"APPLE-SA-2007-03-13","refsource":"APPLE","url":"http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html"},{"name":"RHSA-2007:0009","refsource":"REDHAT","url":"http://www.redhat.com/support/errata/RHSA-2007-0009.html"},{"name":"http://docs.info.apple.com/article.html?artnum=305214","refsource":"CONFIRM","url":"http://docs.info.apple.com/article.html?artnum=305214"},{"name":"23324","refsource":"SECUNIA","url":"http://secunia.com/advisories/23324"},{"name":"flashplayer-multiple-xsrf(29634)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/29634"},{"name":"SUSE-SA:2006:077","refsource":"SUSE","url":"http://lists.suse.com/archive/suse-security-announce/2006-Dec/0006.html"},{"name":"oval:org.mitre.oval:def:11405","refsource":"OVAL","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11405"},{"name":"25467","refsource":"SECUNIA","url":"http://secunia.com/advisories/25467"},{"name":"ADV-2006-4094","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2006/4094"},{"name":"29863","refsource":"OSVDB","url":"http://www.osvdb.org/29863"},{"name":"http://www.adobe.com/support/security/bulletins/apsb06-18.html","refsource":"CONFIRM","url":"http://www.adobe.com/support/security/bulletins/apsb06-18.html"},{"name":"http://www.rapid7.com/advisories/R7-0026.jsp","refsource":"MISC","url":"http://www.rapid7.com/advisories/R7-0026.jsp"},{"name":"20592","refsource":"BID","url":"http://www.securityfocus.com/bid/20592"},{"name":"ADV-2007-0930","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2007/0930"},{"name":"1737","refsource":"SREASON","url":"http://securityreason.com/securityalert/1737"},{"name":"ADV-2007-1999","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2007/1999"},{"name":"23581","refsource":"SECUNIA","url":"http://secunia.com/advisories/23581"},{"name":"20061017 Rapid7 Advisory R7-0026: HTTP Header Injection Vulnerabilities in the Flash Player Plugin","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/448997/100/0/threaded"},{"name":"1017078","refsource":"SECTRACK","url":"http://securitytracker.com/id?1017078"},{"name":"24479","refsource":"SECUNIA","url":"http://secunia.com/advisories/24479"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2006-5330","datePublished":"2006-10-17T21:00:00.000Z","dateReserved":"2006-10-17T00:00:00.000Z","dateUpdated":"2024-08-07T19:48:30.288Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2006-10-17 21:07:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-79","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:flash_player:*:*:linux:*:*:*:*:*","versionEndIncluding":"7.0.63","matchCriteriaId":"FB3055E4-5C68-4A36-8CC6-296ECD32FECD"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:flash_player:*:*:solaris:*:*:*:*:*","versionEndIncluding":"7.0_r67","matchCriteriaId":"030AD994-C027-4290-B592-1A98989CCFE0"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:flash_player:*:*:windows:*:*:*:*:*","versionEndIncluding":"9.0.16","matchCriteriaId":"49581028-11C3-42A6-9532-7D148098B27F"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:flash_player:*:*:mac_os_x:*:*:*:*:*","versionEndIncluding":"9.0.28.0","matchCriteriaId":"BADF6C3D-CB1B-4F6C-A8EF-40DF28C0FC3D"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"5330","Ordinal":"1","Title":"CVE-2006-5330","CVE":"CVE-2006-5330","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"5330","Ordinal":"1","NoteData":"CRLF injection vulnerability in Adobe Flash Player plugin 9.0.16 and earlier for Windows, 7.0.63 and earlier for Linux, 7.x before 7.0 r67 for Solaris, and before 9.0.28.0 for Mac OS X, allows remote attackers to modify HTTP headers of client requests and conduct HTTP Request Splitting attacks via CRLF sequences in arguments to the ActionScript functions (1) XML.addRequestHeader and (2) XML.contentType.  NOTE: the flexibility of the attack varies depending on the type of web browser being used.","Type":"Description","Title":"CVE-2006-5330"},{"CveYear":"2006","CveId":"5330","Ordinal":"2","NoteData":"2006-10-17","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"5330","Ordinal":"3","NoteData":"2018-10-17","Type":"Other","Title":"Modified"}]}}}