Vulnerability Name:

CVE-2006-6955 (CCN-26898)

Assigned:2006-05-30
Published:2006-05-30
Updated:2018-10-30
Summary:Opera allows remote attackers to cause a denial of service (application crash) via a web page that contains a large number of nested marquee tags, a related issue to CVE-2006-2723.
CVSS v3 Severity:5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Low
CVSS v2 Severity:4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
Vulnerability Type:CWE-20
Vulnerability Consequences:Denial of Service
References:Source: CCN
Type: BugTraq Mailing List, Tue May 30 2006 - 07:03:36 CDT
Fire fox dos exploit

Source: CCN
Type: BugTraq Mailing List, Wed May 31 2006 - 08:59:24 CDT
Re: Fire fox dos exploit

Source: CCN
Type: BugTraq Mailing List, Wed May 31 2006 - 12:28:24 CDT
Re: Fire fox dos exploit

Source: CCN
Type: BugTraq Mailing List, Wed May 31 2006 - 13:29:54 CDT
Re: Re: Fire fox dos exploit

Source: CCN
Type: BugTraq Mailing List, Wed May 31 2006 - 15:14:41 CDT
Re: Fire fox dos exploit

Source: BUGTRAQ
Type: Exploit
20060608 Ie opera dos exploit

Source: CCN
Type: BugTraq Mailing List, Thu Jun 08 2006 - 05:06:08 CDT
Ie opera dos exploit

Source: CCN
Type: BugTraq Mailing List, Thu Jun 22 2006 - 19:27:07 CDT
flock d0s exploit remote. beta 1 (v0.7)

Source: MITRE
Type: CNA
CVE-2006-2723

Source: MITRE
Type: CNA
CVE-2006-6954

Source: MITRE
Type: CNA
CVE-2006-6955

Source: MITRE
Type: CNA
CVE-2006-6956

Source: CCN
Type: Flock Web site
Flock - The web browser for you and your friends

Source: CCN
Type: OSVDB ID: 27208
Mozilla Firefox Nested marquee Tag Handling DoS

Source: CCN
Type: OSVDB ID: 58816
Flock Browser Nested marquee Tag Handling DoS

Source: CCN
Type: OSVDB ID: 58817
Microsoft IE Nested marquee Tag Handling DoS

Source: CCN
Type: OSVDB ID: 58818
Opera Nested marquee Tag Handling DoS

Source: CCN
Type: OSVDB ID: 64160
Opera Content Writing Uninitialized Memory Corruption

Source: CCN
Type: BID-18165
Multiple Browser Marquee Denial of Service Vulnerability

Source: CCN
Type: Mozilla Bugzilla Bug 239840
hang when many dl and marquee tags are used. exponential time increase depending on number of dl tags..

Source: XF
Type: UNKNOWN
firefox-marquee-dos(26898)

Source: XF
Type: UNKNOWN
firefox-marquee-dos(26898)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:opera:opera_browser:5.0:*:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:5.0:beta2:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:5.0:beta3:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:5.0:beta4:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:5.0:beta5:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:5.0:beta6:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:5.0:beta7:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:5.0:beta8:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:5.02:*:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:5.10:*:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:5.11:*:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:5.12:*:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:6.0:*:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:6.0:beta1:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:6.0:beta2:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:6.0:tp1:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:6.0:tp2:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:6.0:tp3:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:6.01:*:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:6.1:*:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:6.1:beta1:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:6.02:*:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:6.03:*:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:6.04:*:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:6.05:*:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:6.06:*:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:6.11:*:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:6.12:*:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:7.0:*:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:7.0:beta1:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:7.0:beta1_v2:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:7.0:beta2:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:7.01:*:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:7.02:*:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:7.03:*:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:7.10:*:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:7.10:beta1:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:7.11:*:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:7.11:beta2:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:7.20:*:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:7.20:beta7:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:7.21:*:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:7.22:*:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:7.23:*:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:7.50:*:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:7.50:beta1:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:7.51:*:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:7.52:*:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:7.53:*:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:7.54:*:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:7.54:update1:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:7.54:update2:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:7.60:*:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:8.0:*:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:8.0:beta1:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:8.0:beta2:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:8.0:beta3:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:8.01:*:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:8.02:*:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:8.50:*:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:8.51:*:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:8.52:*:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:8.53:*:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:8.54:*:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:9.0:*:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:9.0:beta1:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:9.0:beta2:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:9.01:*:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:9.02:*:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:9.10:*:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:9.12:*:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:9.20:*:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:9.20:beta1:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:9.21:*:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:9.22:*:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:9.23:*:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:9.24:*:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:9.25:*:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:9.26:*:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:9.27:*:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:9.50:*:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:9.50:beta1:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:9.50:beta2:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:9.51:*:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:9.52:*:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:9.60:*:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:9.60:beta1:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:9.61:*:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:9.62:*:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:9.63:*:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:9.64:*:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:10.00:*:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:10.00:beta1:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:10.00:beta2:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:10.00:beta3:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:10.01:*:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:10.10:*:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:10.10:beta1:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:10.50:*:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:10.50:beta1:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:10.50:beta2:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:10.51:*:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:10.52:*:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:10.53:*:*:*:*:*:*:*
  • OR cpe:/a:opera:opera_browser:10.53:b:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:opera:opera_browser:*:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:internet_explorer:6.0:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:ie:6.0:sp1:*:*:*:*:*:*
  • OR cpe:/a:mozilla:firefox:1.5.0.3:*:*:*:*:*:*:*
  • OR cpe:/a:mozilla:firefox:1.5.0.4:*:*:*:*:*:*:*
  • OR cpe:/a:mozilla:firefox:1.0.8:*:*:*:*:*:*:*
  • OR cpe:/a:mozilla:firefox:2.0.0.3:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    opera opera browser 5.0
    opera opera browser 5.0 beta2
    opera opera browser 5.0 beta3
    opera opera browser 5.0 beta4
    opera opera browser 5.0 beta5
    opera opera browser 5.0 beta6
    opera opera browser 5.0 beta7
    opera opera browser 5.0 beta8
    opera opera browser 5.02
    opera opera browser 5.10
    opera opera browser 5.11
    opera opera browser 5.12
    opera opera browser 6.0
    opera opera browser 6.0 beta1
    opera opera browser 6.0 beta2
    opera opera browser 6.0 tp1
    opera opera browser 6.0 tp2
    opera opera browser 6.0 tp3
    opera opera browser 6.01
    opera opera browser 6.1
    opera opera browser 6.1 beta1
    opera opera browser 6.02
    opera opera browser 6.03
    opera opera browser 6.04
    opera opera browser 6.05
    opera opera browser 6.06
    opera opera browser 6.11
    opera opera browser 6.12
    opera opera browser 7.0
    opera opera browser 7.0 beta1
    opera opera browser 7.0 beta1_v2
    opera opera browser 7.0 beta2
    opera opera browser 7.01
    opera opera browser 7.02
    opera opera browser 7.03
    opera opera browser 7.10
    opera opera browser 7.10 beta1
    opera opera browser 7.11
    opera opera browser 7.11 beta2
    opera opera browser 7.20
    opera opera browser 7.20 beta7
    opera opera browser 7.21
    opera opera browser 7.22
    opera opera browser 7.23
    opera opera browser 7.50
    opera opera browser 7.50 beta1
    opera opera browser 7.51
    opera opera browser 7.52
    opera opera browser 7.53
    opera opera browser 7.54
    opera opera browser 7.54 update1
    opera opera browser 7.54 update2
    opera opera browser 7.60
    opera opera browser 8.0
    opera opera browser 8.0 beta1
    opera opera browser 8.0 beta2
    opera opera browser 8.0 beta3
    opera opera browser 8.01
    opera opera browser 8.02
    opera opera browser 8.50
    opera opera browser 8.51
    opera opera browser 8.52
    opera opera browser 8.53
    opera opera browser 8.54
    opera opera browser 9.0
    opera opera browser 9.0 beta1
    opera opera browser 9.0 beta2
    opera opera browser 9.01
    opera opera browser 9.02
    opera opera browser 9.10
    opera opera browser 9.12
    opera opera browser 9.20
    opera opera browser 9.20 beta1
    opera opera browser 9.21
    opera opera browser 9.22
    opera opera browser 9.23
    opera opera browser 9.24
    opera opera browser 9.25
    opera opera browser 9.26
    opera opera browser 9.27
    opera opera browser 9.50
    opera opera browser 9.50 beta1
    opera opera browser 9.50 beta2
    opera opera browser 9.51
    opera opera browser 9.52
    opera opera browser 9.60
    opera opera browser 9.60 beta1
    opera opera browser 9.61
    opera opera browser 9.62
    opera opera browser 9.63
    opera opera browser 9.64
    opera opera browser 10.00
    opera opera browser 10.00 beta1
    opera opera browser 10.00 beta2
    opera opera browser 10.00 beta3
    opera opera browser 10.01
    opera opera browser 10.10
    opera opera browser 10.10 beta1
    opera opera browser 10.50
    opera opera browser 10.50 beta1
    opera opera browser 10.50 beta2
    opera opera browser 10.51
    opera opera browser 10.52
    opera opera browser 10.53
    opera opera browser 10.53 b
    opera opera browser *
    microsoft ie 6.0
    microsoft ie 6.0 sp1
    mozilla firefox 1.5.0.3
    mozilla firefox 1.5.0.4
    mozilla firefox 1.0.8
    mozilla firefox 2.0.0.3