Unrated severityNVD Advisory· Published Oct 23, 2006· Updated Jun 16, 2026
CVE-2006-5454
CVE-2006-5454
Description
Bugzilla 2.18.x before 2.18.6, 2.20.x before 2.20.3, 2.22.x before 2.22.1, and 2.23.x before 2.23.3 allow remote attackers to obtain (1) the description of arbitrary attachments by viewing the attachment in "diff" mode in attachment.cgi, and (2) the deadline field by viewing the XML format of the bug in show_bug.cgi.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
19cpe:2.3:a:mozilla:bugzilla:2.18:*:*:*:*:*:*:*+ 17 more
- cpe:2.3:a:mozilla:bugzilla:2.18:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:bugzilla:2.18.1:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:bugzilla:2.18.2:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:bugzilla:2.18.3:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:bugzilla:2.18.4:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:bugzilla:2.18.5:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:bugzilla:2.18:rc1:*:*:*:*:*:*
- cpe:2.3:a:mozilla:bugzilla:2.18:rc2:*:*:*:*:*:*
- cpe:2.3:a:mozilla:bugzilla:2.18:rc3:*:*:*:*:*:*
- cpe:2.3:a:mozilla:bugzilla:2.20:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:bugzilla:2.20.1:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:bugzilla:2.20.2:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:bugzilla:2.20:rc1:*:*:*:*:*:*
- cpe:2.3:a:mozilla:bugzilla:2.20:rc2:*:*:*:*:*:*
- cpe:2.3:a:mozilla:bugzilla:2.22:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:bugzilla:2.23:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:bugzilla:2.23.1:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:bugzilla:2.23.2:*:*:*:*:*:*:*
- Range: 2.18.x before 2.18.6, 2.20.x before 2.20.3, 2.22.x before 2.22.1, 2.23.x before 2.23.3
Patches
Vulnerability mechanics
References
13- securitytracker.com/idnvdPatch
- bugzilla.mozilla.org/show_bug.cginvdPatch
- bugzilla.mozilla.org/show_bug.cginvdPatch
- secunia.com/advisories/22409nvd
- secunia.com/advisories/22790nvd
- security.gentoo.org/glsa/glsa-200611-04.xmlnvd
- securityreason.com/securityalert/1760nvd
- www.bugzilla.org/security/2.18.5/nvd
- www.osvdb.org/29546nvd
- www.osvdb.org/29547nvd
- www.securityfocus.com/archive/1/448777/100/100/threadednvd
- www.securityfocus.com/bid/20538nvd
- www.vupen.com/english/advisories/2006/4035nvd
News mentions
0No linked articles in our index yet.