security flaw
Published Nov 8, 2006
6.4
MEDIUMCVSS 2.0
EPSS 2.75%
Description
Mozilla Network Security Service (NSS) library before 3.11.3, as used in Mozilla Firefox before 1.5.0.8, Thunderbird before 1.5.0.8, and SeaMonkey before 1.0.6, when using an RSA key with exponent 3, does not properly handle extra data in a signature, which allows remote attackers to forge signatures for SSL/TLS and email certificates. NOTE: this identifier is for unpatched product versions that were originally intended to be addressed by CVE-2006-4340.
Affected products
No data.
- 1.5
- 1.5
- 1.5
- 1.5.0.1
- 1.5.0.2
- 1.5.0.3
- 1.5.0.4
- 1.5.0.5
- 1.5.0.6
- 1.5.0.7
- 3.11.3
- 1.0
- 1.0
- 1.0
- 1.0
- 1.0.1
- 1.0.2
- 1.0.3
- 1.0.4
- 1.0.5
- 1.5
- 1.5
- 1.5.0.1
- 1.5.0.2
- 1.5.0.3
- 1.5.0.4
- 1.5.0.6
- 1.5.0.7
No data.
Red Hat Enterprise Linux 2.1
seamonkey-0:1.0.6-0.1.el2
Fixed · RHSA-2006:0734
Red Hat Enterprise Linux 3
seamonkey-0:1.0.6-0.1.el3
Fixed · RHSA-2006:0734
Red Hat Enterprise Linux 4
devhelp-0:0.10-0.5.el4
Fixed · RHSA-2006:0734
Red Hat Enterprise Linux 4
firefox-0:1.5.0.8-0.1.el4
Fixed · RHSA-2006:0733
Red Hat Enterprise Linux 4
seamonkey-0:1.0.6-0.1.el4
Fixed · RHSA-2006:0734
Red Hat Enterprise Linux 4
thunderbird-0:1.5.0.8-0.1.el4
Fixed · RHSA-2006:0735
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 2.1 | seamonkey-0:1.0.6-0.1.el2 | Fixed | RHSA-2006:0734 |
| Red Hat Enterprise Linux 3 | seamonkey-0:1.0.6-0.1.el3 | Fixed | RHSA-2006:0734 |
| Red Hat Enterprise Linux 4 | devhelp-0:0.10-0.5.el4 | Fixed | RHSA-2006:0734 |
| Red Hat Enterprise Linux 4 | firefox-0:1.5.0.8-0.1.el4 | Fixed | RHSA-2006:0733 |
| Red Hat Enterprise Linux 4 | seamonkey-0:1.0.6-0.1.el4 | Fixed | RHSA-2006:0734 |
| Red Hat Enterprise Linux 4 | thunderbird-0:1.5.0.8-0.1.el4 | Fixed | RHSA-2006:0735 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:P/I:P/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 2, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (23 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 2, 2026 | 2.75% (0.02754) | 85.72th | v5 (v2026.06.15) |
| Jun 15, 2026 | 2.61% (0.02611) | 83.35th | v5 (v2026.06.15) |
| Mar 30, 2025 | 12.36% (0.12363) | 93.27th | v4 (v2025.03.14) |
| Mar 29, 2025 | 18.54% (0.18536) | 92.18th | v4 (v2025.03.14) |
| Mar 17, 2025 | 12.36% (0.12363) | 93.34th | v4 (v2025.03.14) |
| Feb 27, 2025 | 83.33% (0.83333) | 98.72th | v3 (v2023.03.01) |
| Dec 17, 2024 | 77.02% (0.77019) | 98.42th | v3 (v2023.03.01) |
| Sep 28, 2024 | 38.49% (0.38494) | 97.28th | v3 (v2023.03.01) |
| Jul 14, 2024 | 41.91% (0.41906) | 97.34th | v3 (v2023.03.01) |
| May 20, 2024 | 44.53% (0.44534) | 97.38th | v3 (v2023.03.01) |
| Apr 2, 2024 | 36.89% (0.36887) | 97.08th | v3 (v2023.03.01) |
| Feb 12, 2024 | 37.51% (0.37512) | 97.06th | v3 (v2023.03.01) |
| Nov 27, 2023 | 30.70% (0.30702) | 96.50th | v3 (v2023.03.01) |
| Oct 20, 2023 | 23.25% (0.23251) | 96.00th | v3 (v2023.03.01) |
| Sep 12, 2023 | 2.87% (0.02873) | 89.46th | v3 (v2023.03.01) |
| Aug 5, 2023 | 3.71% (0.03705) | 90.52th | v3 (v2023.03.01) |
| Jun 28, 2023 | 2.53% (0.02526) | 88.64th | v3 (v2023.03.01) |
| May 21, 2023 | 2.70% (0.02700) | 88.93th | v3 (v2023.03.01) |
| Apr 12, 2023 | 2.58% (0.02577) | 88.64th | v3 (v2023.03.01) |
| Mar 7, 2023 | 1.76% (0.01765) | 86.04th | v3 (v2023.03.01) |
| Mar 6, 2023 | 4.36% (0.04358) | 88.02th | v2 (v2022.01.01) |
| Apr 1, 2022 | 4.36% (0.04358) | 86.83th | v2 (v2022.01.01) |
| Feb 4, 2022 | 4.36% (0.04358) | 70.59th | v2 (v2022.01.01) |
No CWE recorded.
References (58)
- ftp://patches.sgi.com/support/free/security/advisories/20061101-01-P vendor-advisoryx_refsource_SGI
- http://rhn.redhat.com/errata/RHSA-2006-0733.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2006-0734.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2006-0735.html vendor-advisoryx_refsource_REDHAT
- http://secunia.com/advisories/22066 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/22722 third-party-advisoryx_refsource_SECUNIAPatchVendor Advisory
- http://secunia.com/advisories/22727 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/22737 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/22763 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/22770 third-party-advisoryx_refsource_SECUNIAPatchVendor Advisory
- http://secunia.com/advisories/22815 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/22817 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/22929 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/22965 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/22980 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/23009 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/23013 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/23197 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/23202 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/23235 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/23263 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/23287 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/23297 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/23883 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/24711 third-party-advisoryx_refsource_SECUNIA
- http://security.gentoo.org/glsa/glsa-200612-06.xml vendor-advisoryx_refsource_GENTOO
- http://security.gentoo.org/glsa/glsa-200612-07.xml vendor-advisoryx_refsource_GENTOO
- http://security.gentoo.org/glsa/glsa-200612-08.xml vendor-advisoryx_refsource_GENTOO
- http://securitytracker.com/id?1017180 vdb-entryx_refsource_SECTRACK
- http://securitytracker.com/id?1017181 vdb-entryx_refsource_SECTRACK
- http://securitytracker.com/id?1017182 vdb-entryx_refsource_SECTRACK
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-102781-1 vendor-advisoryx_refsource_SUNALERT
- http://support.avaya.com/elmodocs2/security/ASA-2006-246.htm x_refsource_CONFIRM
- http://www.debian.org/security/2006/dsa-1224 vendor-advisoryx_refsource_DEBIAN
- http://www.debian.org/security/2006/dsa-1225 vendor-advisoryx_refsource_DEBIAN
- http://www.debian.org/security/2006/dsa-1227 vendor-advisoryx_refsource_DEBIAN
- http://www.kb.cert.org/vuls/id/335392 third-party-advisoryx_refsource_CERT-VNPatchUS Government Resource
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:205 vendor-advisoryx_refsource_MANDRIVA
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:206 vendor-advisoryx_refsource_MANDRIVA
- http://www.mozilla.org/security/announce/2006/mfsa2006-60.html x_refsource_MISCPatch
- http://www.mozilla.org/security/announce/2006/mfsa2006-66.html x_refsource_CONFIRMPatch
- http://www.novell.com/linux/security/advisories/2006_68_mozilla.html vendor-advisoryx_refsource_SUSE
- http://www.ubuntu.com/usn/usn-381-1 vendor-advisoryx_refsource_UBUNTU
- http://www.ubuntu.com/usn/usn-382-1 vendor-advisoryx_refsource_UBUNTU
- http://www.us-cert.gov/cas/techalerts/TA06-312A.html third-party-advisoryx_refsource_CERTPatchUS Government Resource
- http://www.vupen.com/english/advisories/2006/3748 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2006/4387 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2007/0293 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2007/1198 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2008/0083 vdb-entryx_refsource_VUPEN
- http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00771742 vendor-advisoryx_refsource_HP
- https://access.redhat.com/security/cve/CVE-2006-5462 Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=356215 x_refsource_MISCPatch
- https://bugzilla.redhat.com/show_bug.cgi?id=1618211 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/30098 vdb-entryx_refsource_XF
- https://nvd.nist.gov/vuln/detail/CVE-2006-5462
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10478 vdb-entrysignaturex_refsource_OVAL
- https://www.cve.org/CVERecord?id=CVE-2006-5462
Change history (0)
No recorded changes yet.