9.3

CVE-2006-0005

Buffer overflow in the plug-in for Microsoft Windows Media Player (WMP) 9 and 10, when used in browsers other than Internet Explorer and set as the default application to handle media files, allows remote attackers to execute arbitrary code via HTML with an EMBED element containing a long src attribute.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Windows-nt Version datacenter_server
Microsoft ≫ Windows-nt Version datacenter_server Update sp1
Microsoft ≫ Windows-nt Version datacenter_server Update sp2
Microsoft ≫ Windows-nt Version datacenter_server Update sp3
Microsoft ≫ Windows-nt Version datacenter_server Update sp4
Microsoft ≫ Windows-nt Version xp Update sp2 Edition home
Microsoft ≫ Windows-nt Version xp_tablet_pc
Microsoft ≫ Windows-nt Version xp_tablet_pc Update sp1
Microsoft ≫ Windows-nt Version xp_tablet_pc Update sp2
Microsoft ≫ Windows 2000 Update sp1 Edition pro
Microsoft ≫ Windows 2000 Update sp2 Edition pro
Microsoft ≫ Windows 2000 Update sp3 Edition pro
Microsoft ≫ Windows 2000 Update sp4
Microsoft ≫ Windows 2000 Update sp4 Edition pro
Microsoft ≫ Windows 2000 Version -
Microsoft ≫ Windows 2003 Server Version datacenter_edition
Microsoft ≫ Windows 2003 Server Version datacenter_edition_64-bit
Microsoft ≫ Windows 2003 Server Version enterprise_edition
Microsoft ≫ Windows 2003 Server Version enterprise_edition_64-bit
Microsoft ≫ Windows 2003 Server Version standard
Microsoft ≫ Windows 2003 Server Version standard_64-bit
Microsoft ≫ Windows 2003 Server Version web_edition
Microsoft ≫ Windows Server 2000 Version none
Microsoft ≫ Windows Server 2000 Version sp1
Microsoft ≫ Windows Server 2000 Version sp2
Microsoft ≫ Windows Server 2000 Version sp3
Microsoft ≫ Windows Server 2003 Version datacenter_sp1
Microsoft ≫ Windows Server 2003 Version enterprise_sp1
Microsoft ≫ Windows Server 2003 Version standard_sp1
Microsoft ≫ Windows Server 2003 Version web_edition_sp1
Microsoft ≫ Windows Xp Edition home
Microsoft ≫ Windows Xp Edition media_center
Microsoft ≫ Windows Xp Edition pro
Microsoft ≫ Windows Xp Edition x64
Microsoft ≫ Windows Xp Update sp1 Edition home
Microsoft ≫ Windows Xp Update sp1 Edition media_center
Microsoft ≫ Windows Xp Update sp1 Edition pro
Microsoft ≫ Windows Xp Update sp2 Edition media_center
Microsoft ≫ Windows Xp Update sp2 Edition pro
Microsoft ≫ Windows Xp Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 38.67% 0.984
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

http://www.us-cert.gov/cas/techalerts/TA06-045A.html
US Government Resource
http://secunia.com/advisories/18852
Vendor Advisory
http://securitytracker.com/id?1015628
http://www.idefense.com/intelligence/vulnerabilities/display.php?id=393
http://www.kb.cert.org/vuls/id/692060
US Government Resource
http://www.securityfocus.com/bid/16644
http://www.vupen.com/english/advisories/2006/0575
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-006
https://exchange.xforce.ibmcloud.com/vulnerabilities/24493
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1559