CVE-2006-2920
Severity CVSS v4.0:
Pending analysis
Type:
CWE-20
Input Validation
Publication date:
09/06/2006
Last modified:
03/04/2025
Description
Sylpheed-Claws before 2.2.2 and Sylpheed before 2.2.6 allow remote attackers to bypass the URI check functionality and makes it easier to conduct phishing attacks via a URI that begins with a space character.
Impact
Base Score 2.0
2.60
Severity 2.0
LOW
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:sylpheed:sylpheed:*:*:*:*:*:*:*:* | 2.2.5 (including) | |
cpe:2.3:a:sylpheed:sylpheed:2.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:sylpheed:sylpheed:2.0.1:*:*:*:*:*:*:* | ||
cpe:2.3:a:sylpheed:sylpheed:2.0.2:*:*:*:*:*:*:* | ||
cpe:2.3:a:sylpheed:sylpheed:2.0.3:*:*:*:*:*:*:* | ||
cpe:2.3:a:sylpheed:sylpheed:2.1:*:*:*:*:*:*:* | ||
cpe:2.3:a:sylpheed:sylpheed:2.1.1:*:*:*:*:*:*:* | ||
cpe:2.3:a:sylpheed:sylpheed:2.1.2:*:*:*:*:*:*:* | ||
cpe:2.3:a:sylpheed:sylpheed:2.1.3:*:*:*:*:*:*:* | ||
cpe:2.3:a:sylpheed:sylpheed:2.1.4:*:*:*:*:*:*:* | ||
cpe:2.3:a:sylpheed:sylpheed:2.1.5:*:*:*:*:*:*:* | ||
cpe:2.3:a:sylpheed-claws:sylpheed-claws:*:*:*:*:*:*:*:* | 2.2.1 (including) | |
cpe:2.3:a:sylpheed-claws:sylpheed-claws:0.9.4:*:*:*:*:*:*:* | ||
cpe:2.3:a:sylpheed-claws:sylpheed-claws:0.9.5:*:*:*:*:*:*:* | ||
cpe:2.3:a:sylpheed-claws:sylpheed-claws:0.9.6:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://secunia.com/advisories/20476
- http://secunia.com/advisories/20577
- http://sourceforge.net/project/shownotes.php?release_id=422662&group_id=25528
- http://sylpheed.good-day.net/en/news.html%5C
- http://www.vupen.com/english/advisories/2006/2173
- http://www.vupen.com/english/advisories/2006/2283
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27089
- http://secunia.com/advisories/20476
- http://secunia.com/advisories/20577
- http://sourceforge.net/project/shownotes.php?release_id=422662&group_id=25528
- http://sylpheed.good-day.net/en/news.html%5C
- http://www.vupen.com/english/advisories/2006/2173
- http://www.vupen.com/english/advisories/2006/2283
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27089