{"api_version":"1","generated_at":"2026-07-23T10:46:26+00:00","cve":"CVE-2006-6499","urls":{"html":"https://cve.report/CVE-2006-6499","api":"https://cve.report/api/cve/CVE-2006-6499.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-6499","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-6499"},"summary":{"title":"CVE-2006-6499","description":"The js_dtoa function in Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 overwrites memory instead of exiting when the floating point precision is reduced, which allows remote attackers to cause a denial of service via any plugins that reduce the precision.","state":"PUBLISHED","assigner":"redhat","published_at":"2006-12-20 01:28:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-835","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:N/A:P","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://securitytracker.com/id?1017405","name":"http://securitytracker.com/id?1017405","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory","VDB Entry"],"title":"Mozilla Seamonkey Memory Corruption in Layout Engine and Javascript Engine May Let Remote Users Execute Arbitrary Code - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.ubuntu.com/usn/usn-398-2","name":"http://www.ubuntu.com/usn/usn-398-2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"usn/usn-398-2 - Ubuntu: Linux for human beings","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.debian.org/security/2007/dsa-1253","name":"http://www.debian.org/security/2007/dsa-1253","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Debian -- Security Information -- DSA-1253-1 mozilla-firefox","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.debian.org/security/2007/dsa-1265","name":"http://www.debian.org/security/2007/dsa-1265","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Debian -- Security Information -- DSA-1265-1 mozilla","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/23422","name":"http://secunia.com/advisories/23422","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory"],"title":"Mozilla SeaMonkey Multiple Vulnerabilities - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/23672","name":"http://secunia.com/advisories/23672","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory"],"title":"SUSE update for mozilla - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securitytracker.com/id?1017398","name":"http://securitytracker.com/id?1017398","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory","VDB Entry"],"title":"Mozilla Firefox Memory Corruption in Layout Engine and Javascript Engine May Let Remote Users Execute Arbitrary Code - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/23692","name":"http://secunia.com/advisories/23692","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory"],"title":"Gentoo update for seamonkey - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.mozilla.org/security/announce/2006/mfsa2006-68.html","name":"http://www.mozilla.org/security/announce/2006/mfsa2006-68.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"MFSA 2006-68: Crashes with evidence of memory corruption (rv:1.8.0.9/1.8.1.1)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.novell.com/linux/security/advisories/2006_80_mozilla.html","name":"http://www.novell.com/linux/security/advisories/2006_80_mozilla.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Security Announcement","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://secunia.com/advisories/23591","name":"http://secunia.com/advisories/23591","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory"],"title":"Ubuntu update for mozilla-thunderbird - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.ubuntu.com/usn/usn-398-1","name":"http://www.ubuntu.com/usn/usn-398-1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"usn/USN-398-1 - Ubuntu: Linux for human beings","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2008/0083","name":"http://www.vupen.com/english/advisories/2008/0083","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742","name":"http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"HPSBUX02153 SSRT061181 rev.7 - HP-UX Running Firefox, Remote Unauthorized Access or Elevation of Privileges or Denial of Service (DoS) - c00771742 - \n\t\tHP Business Support Center","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.novell.com/linux/security/advisories/2007_06_mozilla.html","name":"http://www.novell.com/linux/security/advisories/2007_06_mozilla.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Security Announcement","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://www.kb.cert.org/vuls/id/427972","name":"http://www.kb.cert.org/vuls/id/427972","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","US Government Resource"],"title":"US-CERT Vulnerability Note VU#427972","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.debian.org/security/2007/dsa-1258","name":"http://www.debian.org/security/2007/dsa-1258","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Debian -- Security Information -- DSA-1258-1 mozilla-thunderbird","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://security.gentoo.org/glsa/glsa-200701-02.xml","name":"http://security.gentoo.org/glsa/glsa-200701-02.xml","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory"],"title":"Gentoo Linux Documentation\n--\n  Mozilla Firefox: Multiple vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/24078","name":"http://secunia.com/advisories/24078","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory"],"title":"Debian update for mozilla-thunderbird - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/23988","name":"http://secunia.com/advisories/23988","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory"],"title":"Debian update for mozilla-firefox - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/21668","name":"http://www.securityfocus.com/bid/21668","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory","VDB Entry"],"title":"Mozilla Firefox/SeaMonkey/Thunderbird Multiple Remote Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.gentoo.org/security/en/glsa/glsa-200701-04.xml","name":"http://www.gentoo.org/security/en/glsa/glsa-200701-04.xml","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Gentoo Linux Documentation\n--\n  SeaMonkey: Multiple vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2007/1124","name":"http://www.vupen.com/english/advisories/2007/1124","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory"],"title":"Webmail- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/23420","name":"http://secunia.com/advisories/23420","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory"],"title":"Mozilla Thunderbird Multiple Vulnerabilities - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/23545","name":"http://secunia.com/advisories/23545","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory"],"title":"SUSE updates for MozillaFirefox and MozillaThunderbird - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/24390","name":"http://secunia.com/advisories/24390","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory"],"title":"Debian update for mozilla - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securitytracker.com/id?1017406","name":"http://securitytracker.com/id?1017406","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory","VDB Entry"],"title":"Mozilla Thunderbird Memory Corruption in Layout Engine and Javascript Engine May Let Remote Users Execute Arbitrary Code - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/23614","name":"http://secunia.com/advisories/23614","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory"],"title":"Gentoo update for mozilla-firefox - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/23589","name":"http://secunia.com/advisories/23589","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory"],"title":"Ubuntu update for firefox - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.us-cert.gov/cas/techalerts/TA06-354A.html","name":"http://www.us-cert.gov/cas/techalerts/TA06-354A.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory","US Government Resource"],"title":"US-CERT Technical Cyber Security Alert TA06-354A -- Mozilla Addresses Multiple Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.ubuntu.com/usn/usn-400-1","name":"http://www.ubuntu.com/usn/usn-400-1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"usn/usn-400-1 - Ubuntu: Linux for human beings","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/23282","name":"http://secunia.com/advisories/23282","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory"],"title":"Mozilla Firefox Multiple Vulnerabilities - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://sunsolve.sun.com/search/document.do?assetkey=1-26-102846-1","name":"http://sunsolve.sun.com/search/document.do?assetkey=1-26-102846-1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"","mime":"","httpstatus":"-1","archivestatus":"404"},{"url":"http://www.vupen.com/english/advisories/2006/5068","name":"http://www.vupen.com/english/advisories/2006/5068","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-6499","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-6499","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"6499","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mozilla","cpe5":"firefox","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T20:26:46.595Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"21668","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/21668"},{"name":"23672","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/23672"},{"name":"ADV-2006-5068","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2006/5068"},{"name":"1017398","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1017398"},{"name":"DSA-1265","tags":["vendor-advisory","x_refsource_DEBIAN","x_transferred"],"url":"http://www.debian.org/security/2007/dsa-1265"},{"name":"24078","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/24078"},{"name":"23692","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/23692"},{"name":"USN-398-2","tags":["vendor-advisory","x_refsource_UBUNTU","x_transferred"],"url":"http://www.ubuntu.com/usn/usn-398-2"},{"name":"GLSA-200701-04","tags":["vendor-advisory","x_refsource_GENTOO","x_transferred"],"url":"http://www.gentoo.org/security/en/glsa/glsa-200701-04.xml"},{"name":"23282","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/23282"},{"name":"24390","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/24390"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.mozilla.org/security/announce/2006/mfsa2006-68.html"},{"name":"23422","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/23422"},{"name":"HPSBUX02153","tags":["vendor-advisory","x_refsource_HP","x_transferred"],"url":"http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742"},{"name":"23591","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/23591"},{"name":"ADV-2007-1124","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2007/1124"},{"name":"1017405","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1017405"},{"name":"23614","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/23614"},{"name":"1017406","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1017406"},{"name":"USN-398-1","tags":["vendor-advisory","x_refsource_UBUNTU","x_transferred"],"url":"http://www.ubuntu.com/usn/usn-398-1"},{"name":"ADV-2008-0083","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2008/0083"},{"name":"23420","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/23420"},{"name":"SUSE-SA:2006:080","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://www.novell.com/linux/security/advisories/2006_80_mozilla.html"},{"name":"VU#427972","tags":["third-party-advisory","x_refsource_CERT-VN","x_transferred"],"url":"http://www.kb.cert.org/vuls/id/427972"},{"name":"23545","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/23545"},{"name":"102846","tags":["vendor-advisory","x_refsource_SUNALERT","x_transferred"],"url":"http://sunsolve.sun.com/search/document.do?assetkey=1-26-102846-1"},{"name":"TA06-354A","tags":["third-party-advisory","x_refsource_CERT","x_transferred"],"url":"http://www.us-cert.gov/cas/techalerts/TA06-354A.html"},{"name":"23589","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/23589"},{"name":"DSA-1253","tags":["vendor-advisory","x_refsource_DEBIAN","x_transferred"],"url":"http://www.debian.org/security/2007/dsa-1253"},{"name":"DSA-1258","tags":["vendor-advisory","x_refsource_DEBIAN","x_transferred"],"url":"http://www.debian.org/security/2007/dsa-1258"},{"name":"SSRT061181","tags":["vendor-advisory","x_refsource_HP","x_transferred"],"url":"http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742"},{"name":"SUSE-SA:2007:006","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://www.novell.com/linux/security/advisories/2007_06_mozilla.html"},{"name":"23988","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/23988"},{"name":"GLSA-200701-02","tags":["vendor-advisory","x_refsource_GENTOO","x_transferred"],"url":"http://security.gentoo.org/glsa/glsa-200701-02.xml"},{"name":"USN-400-1","tags":["vendor-advisory","x_refsource_UBUNTU","x_transferred"],"url":"http://www.ubuntu.com/usn/usn-400-1"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2006-12-19T00:00:00.000Z","descriptions":[{"lang":"en","value":"The js_dtoa function in Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 overwrites memory instead of exiting when the floating point precision is reduced, which allows remote attackers to cause a denial of service via any plugins that reduce the precision."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2006-12-22T10:00:00.000Z","orgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","shortName":"redhat"},"references":[{"name":"21668","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/21668"},{"name":"23672","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/23672"},{"name":"ADV-2006-5068","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2006/5068"},{"name":"1017398","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1017398"},{"name":"DSA-1265","tags":["vendor-advisory","x_refsource_DEBIAN"],"url":"http://www.debian.org/security/2007/dsa-1265"},{"name":"24078","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/24078"},{"name":"23692","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/23692"},{"name":"USN-398-2","tags":["vendor-advisory","x_refsource_UBUNTU"],"url":"http://www.ubuntu.com/usn/usn-398-2"},{"name":"GLSA-200701-04","tags":["vendor-advisory","x_refsource_GENTOO"],"url":"http://www.gentoo.org/security/en/glsa/glsa-200701-04.xml"},{"name":"23282","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/23282"},{"name":"24390","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/24390"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.mozilla.org/security/announce/2006/mfsa2006-68.html"},{"name":"23422","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/23422"},{"name":"HPSBUX02153","tags":["vendor-advisory","x_refsource_HP"],"url":"http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742"},{"name":"23591","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/23591"},{"name":"ADV-2007-1124","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2007/1124"},{"name":"1017405","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1017405"},{"name":"23614","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/23614"},{"name":"1017406","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1017406"},{"name":"USN-398-1","tags":["vendor-advisory","x_refsource_UBUNTU"],"url":"http://www.ubuntu.com/usn/usn-398-1"},{"name":"ADV-2008-0083","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2008/0083"},{"name":"23420","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/23420"},{"name":"SUSE-SA:2006:080","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://www.novell.com/linux/security/advisories/2006_80_mozilla.html"},{"name":"VU#427972","tags":["third-party-advisory","x_refsource_CERT-VN"],"url":"http://www.kb.cert.org/vuls/id/427972"},{"name":"23545","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/23545"},{"name":"102846","tags":["vendor-advisory","x_refsource_SUNALERT"],"url":"http://sunsolve.sun.com/search/document.do?assetkey=1-26-102846-1"},{"name":"TA06-354A","tags":["third-party-advisory","x_refsource_CERT"],"url":"http://www.us-cert.gov/cas/techalerts/TA06-354A.html"},{"name":"23589","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/23589"},{"name":"DSA-1253","tags":["vendor-advisory","x_refsource_DEBIAN"],"url":"http://www.debian.org/security/2007/dsa-1253"},{"name":"DSA-1258","tags":["vendor-advisory","x_refsource_DEBIAN"],"url":"http://www.debian.org/security/2007/dsa-1258"},{"name":"SSRT061181","tags":["vendor-advisory","x_refsource_HP"],"url":"http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742"},{"name":"SUSE-SA:2007:006","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://www.novell.com/linux/security/advisories/2007_06_mozilla.html"},{"name":"23988","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/23988"},{"name":"GLSA-200701-02","tags":["vendor-advisory","x_refsource_GENTOO"],"url":"http://security.gentoo.org/glsa/glsa-200701-02.xml"},{"name":"USN-400-1","tags":["vendor-advisory","x_refsource_UBUNTU"],"url":"http://www.ubuntu.com/usn/usn-400-1"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"secalert@redhat.com","ID":"CVE-2006-6499","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The js_dtoa function in Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 overwrites memory instead of exiting when the floating point precision is reduced, which allows remote attackers to cause a denial of service via any plugins that reduce the precision."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"21668","refsource":"BID","url":"http://www.securityfocus.com/bid/21668"},{"name":"23672","refsource":"SECUNIA","url":"http://secunia.com/advisories/23672"},{"name":"ADV-2006-5068","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2006/5068"},{"name":"1017398","refsource":"SECTRACK","url":"http://securitytracker.com/id?1017398"},{"name":"DSA-1265","refsource":"DEBIAN","url":"http://www.debian.org/security/2007/dsa-1265"},{"name":"24078","refsource":"SECUNIA","url":"http://secunia.com/advisories/24078"},{"name":"23692","refsource":"SECUNIA","url":"http://secunia.com/advisories/23692"},{"name":"USN-398-2","refsource":"UBUNTU","url":"http://www.ubuntu.com/usn/usn-398-2"},{"name":"GLSA-200701-04","refsource":"GENTOO","url":"http://www.gentoo.org/security/en/glsa/glsa-200701-04.xml"},{"name":"23282","refsource":"SECUNIA","url":"http://secunia.com/advisories/23282"},{"name":"24390","refsource":"SECUNIA","url":"http://secunia.com/advisories/24390"},{"name":"http://www.mozilla.org/security/announce/2006/mfsa2006-68.html","refsource":"CONFIRM","url":"http://www.mozilla.org/security/announce/2006/mfsa2006-68.html"},{"name":"23422","refsource":"SECUNIA","url":"http://secunia.com/advisories/23422"},{"name":"HPSBUX02153","refsource":"HP","url":"http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742"},{"name":"23591","refsource":"SECUNIA","url":"http://secunia.com/advisories/23591"},{"name":"ADV-2007-1124","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2007/1124"},{"name":"1017405","refsource":"SECTRACK","url":"http://securitytracker.com/id?1017405"},{"name":"23614","refsource":"SECUNIA","url":"http://secunia.com/advisories/23614"},{"name":"1017406","refsource":"SECTRACK","url":"http://securitytracker.com/id?1017406"},{"name":"USN-398-1","refsource":"UBUNTU","url":"http://www.ubuntu.com/usn/usn-398-1"},{"name":"ADV-2008-0083","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2008/0083"},{"name":"23420","refsource":"SECUNIA","url":"http://secunia.com/advisories/23420"},{"name":"SUSE-SA:2006:080","refsource":"SUSE","url":"http://www.novell.com/linux/security/advisories/2006_80_mozilla.html"},{"name":"VU#427972","refsource":"CERT-VN","url":"http://www.kb.cert.org/vuls/id/427972"},{"name":"23545","refsource":"SECUNIA","url":"http://secunia.com/advisories/23545"},{"name":"102846","refsource":"SUNALERT","url":"http://sunsolve.sun.com/search/document.do?assetkey=1-26-102846-1"},{"name":"TA06-354A","refsource":"CERT","url":"http://www.us-cert.gov/cas/techalerts/TA06-354A.html"},{"name":"23589","refsource":"SECUNIA","url":"http://secunia.com/advisories/23589"},{"name":"DSA-1253","refsource":"DEBIAN","url":"http://www.debian.org/security/2007/dsa-1253"},{"name":"DSA-1258","refsource":"DEBIAN","url":"http://www.debian.org/security/2007/dsa-1258"},{"name":"SSRT061181","refsource":"HP","url":"http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742"},{"name":"SUSE-SA:2007:006","refsource":"SUSE","url":"http://www.novell.com/linux/security/advisories/2007_06_mozilla.html"},{"name":"23988","refsource":"SECUNIA","url":"http://secunia.com/advisories/23988"},{"name":"GLSA-200701-02","refsource":"GENTOO","url":"http://security.gentoo.org/glsa/glsa-200701-02.xml"},{"name":"USN-400-1","refsource":"UBUNTU","url":"http://www.ubuntu.com/usn/usn-400-1"}]}}}},"cveMetadata":{"assignerOrgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","assignerShortName":"redhat","cveId":"CVE-2006-6499","datePublished":"2006-12-20T01:00:00.000Z","dateReserved":"2006-12-13T00:00:00.000Z","dateUpdated":"2024-08-07T20:26:46.595Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2006-12-20 01:28:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-835","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:N/A:P","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*","versionStartIncluding":"1.5","versionEndExcluding":"1.5.0.9","matchCriteriaId":"A3FAAB80-9C12-47E9-BE5A-7763004F7A7D"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*","versionStartIncluding":"2.0","versionEndExcluding":"2.0.0.1","matchCriteriaId":"C911462E-7F1B-4C32-82FB-40816E7B4592"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:*","versionEndExcluding":"1.0.7","matchCriteriaId":"BD3C5C83-4F57-4D3A-A872-4F5BE7CD634B"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*","versionEndExcluding":"1.5.0.9","matchCriteriaId":"07C3E97B-591F-4A68-B901-441FA3540400"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:debian:debian_linux:3.1:*:*:*:*:*:*:*","matchCriteriaId":"A2E0C1F8-31F5-4F61-9DF7-E49B43D3C873"},{"vulnerable":true,"criteria":"cpe:2.3:o:debian:debian_linux:4.0:*:*:*:*:*:*:*","matchCriteriaId":"0F92AB32-E7DE-43F4-B877-1F41FA162EC7"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:canonical:ubuntu_linux:5.10:*:*:*:*:*:*:*","matchCriteriaId":"0FA3A32E-445A-4D39-A8D5-75F5370AD23D"},{"vulnerable":true,"criteria":"cpe:2.3:o:canonical:ubuntu_linux:6.06:*:*:*:lts:*:*:*","matchCriteriaId":"5C18C3CD-969B-4AA3-AE3A-BA4A188F8BFF"},{"vulnerable":true,"criteria":"cpe:2.3:o:canonical:ubuntu_linux:6.10:*:*:*:*:*:*:*","matchCriteriaId":"23E304C9-F780-4358-A58D-1E4C93977704"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"6499","Ordinal":"1","Title":"CVE-2006-6499","CVE":"CVE-2006-6499","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"6499","Ordinal":"1","NoteData":"The js_dtoa function in Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 overwrites memory instead of exiting when the floating point precision is reduced, which allows remote attackers to cause a denial of service via any plugins that reduce the precision.","Type":"Description","Title":"CVE-2006-6499"},{"CveYear":"2006","CveId":"6499","Ordinal":"2","NoteData":"2006-12-19","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"6499","Ordinal":"3","NoteData":"2006-12-22","Type":"Other","Title":"Modified"}]}}}