9.3

CVE-2006-0005

Buffer overflow in the plug-in for Microsoft Windows Media Player (WMP) 9 and 10, when used in browsers other than Internet Explorer and set as the default application to handle media files, allows remote attackers to execute arbitrary code via HTML with an EMBED element containing a long src attribute.

Data is provided by the National Vulnerability Database (NVD)
MicrosoftWindows-nt Versiondatacenter_server
MicrosoftWindows-nt Versiondatacenter_server Updatesp1
MicrosoftWindows-nt Versiondatacenter_server Updatesp2
MicrosoftWindows-nt Versiondatacenter_server Updatesp3
MicrosoftWindows-nt Versiondatacenter_server Updatesp4
MicrosoftWindows-nt Versionxp Updatesp2 Editionhome
MicrosoftWindows-nt Versionxp_tablet_pc
MicrosoftWindows-nt Versionxp_tablet_pc Updatesp1
MicrosoftWindows-nt Versionxp_tablet_pc Updatesp2
MicrosoftWindows 2000 Updatesp1 Editionpro
MicrosoftWindows 2000 Updatesp2 Editionpro
MicrosoftWindows 2000 Updatesp3 Editionpro
MicrosoftWindows 2000 Updatesp4
MicrosoftWindows 2000 Updatesp4 Editionpro
MicrosoftWindows 2000 Version-
MicrosoftWindows 2003 Server Versiondatacenter_edition
MicrosoftWindows 2003 Server Versiondatacenter_edition_64-bit
MicrosoftWindows 2003 Server Versionenterprise_edition
MicrosoftWindows 2003 Server Versionenterprise_edition_64-bit
MicrosoftWindows 2003 Server Versionstandard
MicrosoftWindows 2003 Server Versionstandard_64-bit
MicrosoftWindows 2003 Server Versionweb_edition
MicrosoftWindows Server 2000 Versionnone
MicrosoftWindows Server 2003 Versiondatacenter_sp1
MicrosoftWindows Server 2003 Versionenterprise_sp1
MicrosoftWindows Server 2003 Versionstandard_sp1
MicrosoftWindows Server 2003 Versionweb_edition_sp1
MicrosoftWindows Xp Editionhome
MicrosoftWindows Xp Editionmedia_center
MicrosoftWindows Xp Editionpro
MicrosoftWindows Xp Editionx64
MicrosoftWindows Xp Updatesp1 Editionhome
MicrosoftWindows Xp Updatesp1 Editionmedia_center
MicrosoftWindows Xp Updatesp1 Editionpro
MicrosoftWindows Xp Updatesp2 Editionmedia_center
MicrosoftWindows Xp Updatesp2 Editionpro
MicrosoftWindows Xp Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 82.19% 0.992
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.