CVE-2006-2778

Source
https://nvd.nist.gov/vuln/detail/CVE-2006-2778
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2006-2778.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2006-2778
Downstream
Published
2006-06-02T18:02:00Z
Modified
2025-08-09T20:01:27Z
Summary
[none]
Details

The crypto.signText function in Mozilla Firefox and Thunderbird before 1.5.0.4 allows remote attackers to execute arbitrary code via certain optional Certificate Authority name arguments, which causes an invalid array index and triggers a buffer overflow.

References

Affected packages