CVE-2006-2920

UnknownEPSS 1.41%

Last modified

CVE-2006-2920 is a vulnerability of currently unknown severity. Sylpheed-Claws before 2.2.2 and Sylpheed before 2.2.6 allow remote attackers to bypass the URI check functionality and makes it easier to conduct phishing attacks via a URI that begins with a space character.. EPSS estimates a 1.41% chance of exploitation in the next 30 days.

Description

Sylpheed-Claws before 2.2.2 and Sylpheed before 2.2.6 allow remote attackers to bypass the URI check functionality and makes it easier to conduct phishing attacks via a URI that begins with a space character.

Metrics

EPSS Probability
1.41%

69.2th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
SylpheedSylpheed<= 2.2.5
SylpheedSylpheed2.0
SylpheedSylpheed2.0.1
SylpheedSylpheed2.0.2
SylpheedSylpheed2.0.3
SylpheedSylpheed2.1
SylpheedSylpheed2.1.1
SylpheedSylpheed2.1.2
SylpheedSylpheed2.1.3
SylpheedSylpheed2.1.4
SylpheedSylpheed2.1.5
Sylpheed-ClawsSylpheed-Claws<= 2.2.1
Sylpheed-ClawsSylpheed-Claws0.9.4
Sylpheed-ClawsSylpheed-Claws0.9.5
Sylpheed-ClawsSylpheed-Claws0.9.6
Sylpheed-ClawsSylpheed-Claws1.0.2

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2006-2920?
Sylpheed-Claws before 2.2.2 and Sylpheed before 2.2.6 allow remote attackers to bypass the URI check functionality and makes it easier to conduct phishing attacks via a URI that begins with a space character.
How severe is CVE-2006-2920?
Severity scoring for CVE-2006-2920 is pending analysis. The EPSS model estimates a 1.41% probability of exploitation in the next 30 days.
How do I fix CVE-2006-2920?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2006-2920?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST