Vulnerability Name: | CVE-2006-2786 (CCN-26844) | ||||||||||||||||||||||||||||||||||||||||
Assigned: | 2006-06-01 | ||||||||||||||||||||||||||||||||||||||||
Published: | 2006-06-01 | ||||||||||||||||||||||||||||||||||||||||
Updated: | 2018-10-18 | ||||||||||||||||||||||||||||||||||||||||
Summary: | HTTP response smuggling vulnerability in Mozilla Firefox and Thunderbird before 1.5.0.4, when used with certain proxy servers, allows remote attackers to cause Firefox to interpret certain responses as if they were responses from two different sites via (1) invalid HTTP response headers with spaces between the header name and the colon, which might not be ignored in some cases, or (2) HTTP 1.1 headers through an HTTP 1.0 proxy, which are ignored by the proxy but processed by the client. | ||||||||||||||||||||||||||||||||||||||||
CVSS v3 Severity: | 3.7 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||||||||||||||||||||||||||||||||||
CVSS v2 Severity: | 2.6 Low (CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N)
| ||||||||||||||||||||||||||||||||||||||||
Vulnerability Type: | CWE-Other | ||||||||||||||||||||||||||||||||||||||||
Vulnerability Consequences: | Other | ||||||||||||||||||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2006-2786 Source: CCN Type: RHSA-2006-0578 seamonkey security update (was mozilla) Source: CCN Type: RHSA-2006-0594 seamonkey security update (was mozilla) Source: CCN Type: RHSA-2006-0609 seamonkey security update Source: REDHAT Type: UNKNOWN RHSA-2006:0609 Source: CCN Type: RHSA-2006-0610 firefox security update Source: CCN Type: RHSA-2006-0611 thunderbird security update Source: CCN Type: SA20376 Firefox Multiple Vulnerabilities Source: SECUNIA Type: UNKNOWN 20376 Source: CCN Type: SA20382 Thunderbird Multiple Vulnerabilities Source: SECUNIA Type: UNKNOWN 20382 Source: SECUNIA Type: UNKNOWN 20561 Source: SECUNIA Type: UNKNOWN 20709 Source: SECUNIA Type: UNKNOWN 21134 Source: SECUNIA Type: UNKNOWN 21176 Source: SECUNIA Type: UNKNOWN 21178 Source: SECUNIA Type: UNKNOWN 21183 Source: SECUNIA Type: UNKNOWN 21188 Source: SECUNIA Type: UNKNOWN 21269 Source: SECUNIA Type: UNKNOWN 21270 Source: SECUNIA Type: UNKNOWN 21324 Source: SECUNIA Type: UNKNOWN 21336 Source: SECUNIA Type: UNKNOWN 21532 Source: SECUNIA Type: UNKNOWN 21631 Source: SECUNIA Type: UNKNOWN 22065 Source: SECUNIA Type: UNKNOWN 22066 Source: CCN Type: SECTRACK ID: 1016202 Mozilla Firefox Bugs Permit Arbitrary Code Execution, Cross-Site Scripting, and HTTP Response Smuggling Source: SECTRACK Type: UNKNOWN 1016202 Source: CCN Type: SECTRACK ID: 1016214 Mozilla Thunderbird Bugs Permit Arbitrary Code Execution, Cross-Site Scripting, and HTTP Response Smuggling Source: SECTRACK Type: UNKNOWN 1016214 Source: CCN Type: ASA-2006-146 seamonkey security update (was mozilla) (RHSA-2006-0578) Source: CCN Type: ASA-2006-151 firefox seamonkey and thunderbird security update (RHSA-2006-0609 RHSA-2006-0610 and RHSA-2006-0611) Source: CCN Type: ASA-2006-208 seamonkey security update (was mozilla) (RHSA-2006-0594) Source: CCN Type: ASA-2006-259 HP-UX Firefox Vulnerabilities Source: CCN Type: ASA-2007-097 HP-UX Running Firefox Remote Unauthorized Access or Elevation of Privileges or Denial of Service (DoS) (HPSBUX02153) Source: CCN Type: ASA-2007-135 HP-UX Running Thunderbird Remote Unauthorized Access or Elevation of Privileges or Denial of Service (HPSBUX02156) Source: DEBIAN Type: UNKNOWN DSA-1118 Source: DEBIAN Type: UNKNOWN DSA-1120 Source: DEBIAN Type: UNKNOWN DSA-1134 Source: DEBIAN Type: DSA-1118 mozilla -- several vulnerabilities Source: DEBIAN Type: DSA-1120 mozilla-firefox -- several vulnerabilities Source: DEBIAN Type: DSA-1134 mozilla-thunderbird -- several vulnerabilities Source: CCN Type: GLSA-200606-12 Mozilla Firefox: Multiple vulnerabilities Source: GENTOO Type: UNKNOWN GLSA-200606-12 Source: CCN Type: GLSA-200606-21 Mozilla Thunderbird: Multiple vulnerabilities Source: GENTOO Type: UNKNOWN GLSA-200606-21 Source: CCN Type: GLSA-200703-05 Mozilla Suite: Multiple vulnerabilities Source: MANDRIVA Type: UNKNOWN MDKSA-2006:143 Source: MANDRIVA Type: UNKNOWN MDKSA-2006:145 Source: CCN Type: MFSA 2006-33 HTTP response smuggling Source: CONFIRM Type: Vendor Advisory http://www.mozilla.org/security/announce/2006/mfsa2006-33.html Source: SUSE Type: UNKNOWN SUSE-SA:2006:035 Source: REDHAT Type: UNKNOWN RHSA-2006:0578 Source: REDHAT Type: UNKNOWN RHSA-2006:0594 Source: REDHAT Type: UNKNOWN RHSA-2006:0610 Source: REDHAT Type: UNKNOWN RHSA-2006:0611 Source: BUGTRAQ Type: UNKNOWN 20060602 rPSA-2006-0091-1 firefox thunderbird Source: HP Type: UNKNOWN SSRT061236 Source: HP Type: UNKNOWN SSRT061181 Source: BID Type: UNKNOWN 18228 Source: CCN Type: BID-18228 Mozilla Firefox, SeaMonkey, Camino, and Thunderbird Multiple Remote Vulnerabilities Source: CCN Type: USN-296-1 Firefox vulnerabilities Source: CCN Type: USN-296-2 Firefox vulnerabilities Source: CCN Type: USN-297-1 Thunderbird vulnerabilities Source: CCN Type: USN-297-2 Thunderbird extensions update for recent security update Source: CCN Type: USN-297-3 Thunderbird vulnerabilities Source: CCN Type: USN-323-1 Mozilla vulnerabilities Source: VUPEN Type: UNKNOWN ADV-2006-2106 Source: VUPEN Type: UNKNOWN ADV-2006-3748 Source: VUPEN Type: UNKNOWN ADV-2006-3749 Source: VUPEN Type: UNKNOWN ADV-2008-0083 Source: XF Type: UNKNOWN mozilla-http-response-smuggling(26844) Source: XF Type: UNKNOWN mozilla-http-response-smuggling(26844) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:9966 Source: UBUNTU Type: UNKNOWN USN-296-1 Source: UBUNTU Type: UNKNOWN USN-296-2 Source: UBUNTU Type: UNKNOWN USN-297-1 Source: UBUNTU Type: UNKNOWN USN-323-1 Source: SUSE Type: SUSE-SA:2006:035 Mozilla browser security problems | ||||||||||||||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration RedHat 1: Configuration RedHat 2: Configuration RedHat 3: Configuration RedHat 4: Configuration RedHat 5: Configuration CCN 1: ![]() | ||||||||||||||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||||||
BACK |