Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2006-6499

17
FAUCET Score

CVE-2006-6499 describes a denial-of-service vulnerability in the js_dtoa function of Mozilla Firefox, Thunderbird, and SeaMonkey. The flaw allows remote attackers to crash affected applications by using plugins that reduce floating-point precision, leading to memory overwrites. With a CVSS score of 4.3, this vulnerability is of medium complexity and requires user interaction, but only results in a denial of service. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
>= 1.5, < 1.5.0.9CPE matchmatch criteria
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
>= 2.0, < 2.0.0.1CPE matchmatch criteria
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
< 1.0.7CPE matchmatch criteria
cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:*
< 1.5.0.9CPE matchmatch criteria
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
3.1CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:3.1:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

4.3MEDIUM

AV:N/AC:M/Au:N/C:N/I:N/A:P

Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
PARTIAL
Access Vector
NETWORK
Access Complexity
MEDIUM
Authentication
NONE
Exploitability Score
8.6
Impact Score
2.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
3.84%
Probability of exploitation in next 30 days
EPSS Percentile
89.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0384 is in the 85th percentile among its peer group of 19,958 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (1)

mozillavendor investigatingvia nvd_reference
View patch

References

h20000.www2.hp.com / bizsupport/TechSupport/Document.jsp
Broken Link
secunia.com / advisories/23282
Broken LinkThird Party Advisory
secunia.com / advisories/23420
Broken LinkThird Party Advisory
secunia.com / advisories/23422
Broken LinkThird Party Advisory
secunia.com / advisories/23545
Broken LinkThird Party Advisory
secunia.com / advisories/23589
Broken LinkThird Party Advisory
secunia.com / advisories/23591
Broken LinkThird Party Advisory
secunia.com / advisories/23614
Broken LinkThird Party Advisory
secunia.com / advisories/23672
Broken LinkThird Party Advisory
secunia.com / advisories/23692
Broken LinkThird Party Advisory
secunia.com / advisories/23988
Broken LinkThird Party Advisory
secunia.com / advisories/24078
Broken LinkThird Party Advisory
secunia.com / advisories/24390
Broken LinkThird Party Advisory
security.gentoo.org / glsa/glsa-200701-02.xml
Broken LinkThird Party Advisory
securitytracker.com / id
Broken LinkThird Party AdvisoryVDB Entry
securitytracker.com / id
Broken LinkThird Party AdvisoryVDB Entry
securitytracker.com / id
Broken LinkThird Party AdvisoryVDB Entry
sunsolve.sun.com / search/document.do
Broken Link
debian.org / security/2007/dsa-1253
Third Party Advisory
debian.org / security/2007/dsa-1258
Third Party Advisory
debian.org / security/2007/dsa-1265
Third Party Advisory
gentoo.org / security/en/glsa/glsa-200701-04.xml
Third Party Advisory
kb.cert.org / vuls/id/427972
Third Party AdvisoryUS Government Resource
mozilla.org / security/announce/2006/mfsa2006-68.html
Vendor Advisory
novell.com / linux/security/advisories/2006_80_mozilla.html
Broken Link
novell.com / linux/security/advisories/2007_06_mozilla.html
Broken Link
securityfocus.com / bid/21668
Broken LinkThird Party AdvisoryVDB Entry
ubuntu.com / usn/usn-398-1
Third Party Advisory
ubuntu.com / usn/usn-398-2
Third Party Advisory
ubuntu.com / usn/usn-400-1
Third Party Advisory
us-cert.gov / cas/techalerts/TA06-354A.html
Broken LinkThird Party AdvisoryUS Government Resource
vupen.com / english/advisories/2006/5068
Broken LinkThird Party Advisory
vupen.com / english/advisories/2007/1124
Broken LinkThird Party Advisory
vupen.com / english/advisories/2008/0083
Broken LinkThird Party Advisory