CVE-2006-6146
Estado: ModificadaBaja (2.6)—
Buffer overflow in the HPDF_Page_Circle function in hpdf_page_operator.c in Takeshi Kanno Haru Free PDF Library (libharu2, aka libharu) 2.0.7 and earlier allows context-dependent attackers to cause a denial of service (application crash) via certain arguments that yield a large amount of PDF data, as demonstrated by a filled circle.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:H/Au:N/C:N/I:N/A:P
- Puntuación base: 2.6
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.24%
- Percentil entre todas las CVEs puntuadas: 68
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- NVD-CWE-Other
Referencias
- http://sourceforge.net/project/shownotes.php?release_id=465886
- http://sourceforge.net/tracker/index.php?func=detail&aid=1597538&group_id=83044&atid=568129
- http://www.securityfocus.com/bid/21259
- http://www.vupen.com/english/advisories/2006/4675
- http://sourceforge.net/project/shownotes.php?release_id=465886
- http://sourceforge.net/tracker/index.php?func=detail&aid=1597538&group_id=83044&atid=568129
- http://www.securityfocus.com/bid/21259
- http://www.vupen.com/english/advisories/2006/4675
JSON original (NVD)
Mostrar
{
"id": "CVE-2006-6146",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 2.6,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:H/Au:N/C:N/I:N/A:P",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "HIGH",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "LOW",
"obtainAllPrivilege": false,
"exploitabilityScore": 4.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2006-11-28T23:28:00.000",
"references": [
{
"url": "http://sourceforge.net/project/shownotes.php?release_id=465886",
"tags": [
"Patch"
],
"source": "cve@mitre.org"
},
{
"url": "http://sourceforge.net/tracker/index.php?func=detail&aid=1597538&group_id=83044&atid=568129",
"tags": [
"Patch"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/21259",
"tags": [
"Patch"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2006/4675",
"source": "cve@mitre.org"
},
{
"url": "http://sourceforge.net/project/shownotes.php?release_id=465886",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://sourceforge.net/tracker/index.php?func=detail&aid=1597538&group_id=83044&atid=568129",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/21259",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2006/4675",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Buffer overflow in the HPDF_Page_Circle function in hpdf_page_operator.c in Takeshi Kanno Haru Free PDF Library (libharu2, aka libharu) 2.0.7 and earlier allows context-dependent attackers to cause a denial of service (application crash) via certain arguments that yield a large amount of PDF data, as demonstrated by a filled circle."
},
{
"lang": "es",
"value": "Desbordamiento de búfer en la función HPDF_Page_Circle en hpdf_page_operator.c en Takeshi Kanno Haru Free PDF Library (libharu2, también conocida como libharu) 2.0.7 y anteriores permite a atacantes dependientes de contexto provocar una denegación de servicio (caída de la aplicación) mediante ciertos argumentos que producen una gran cantidad de información PDF, como ha sido demostrado por un círculo relleno."
}
],
"lastModified": "2026-06-16T22:32:33.723",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:takeshi_kanno:haru_free_pdf_library:2.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BFF3BB92-218B-4F05-A58A-C4873B675E95"
},
{
"criteria": "cpe:2.3:a:takeshi_kanno:haru_free_pdf_library:2.0.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "650CE745-75DA-49A5-AD26-E8A5C27D2284"
},
{
"criteria": "cpe:2.3:a:takeshi_kanno:haru_free_pdf_library:2.0.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FF02B8E6-5D2C-42DD-B0DA-51617CDAE7C7"
},
{
"criteria": "cpe:2.3:a:takeshi_kanno:haru_free_pdf_library:2.0.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7F61B8EB-37BF-4E45-903C-C25DD1100FAC"
},
{
"criteria": "cpe:2.3:a:takeshi_kanno:haru_free_pdf_library:2.0.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5C1974B3-3902-4C53-B6EF-D85B8BC815C1"
},
{
"criteria": "cpe:2.3:a:takeshi_kanno:haru_free_pdf_library:2.0.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "419260A7-5934-4FF1-9A60-6B7FEDEE8D3D"
},
{
"criteria": "cpe:2.3:a:takeshi_kanno:haru_free_pdf_library:2.0.6:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A1052571-E29C-482F-8512-7F7A448A7274"
},
{
"criteria": "cpe:2.3:a:takeshi_kanno:haru_free_pdf_library:2.0.7:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "02D21F87-42A4-45AF-9A39-9A59631F8824"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}