9.3
CVE-2006-0005
- EPSS 82.19%
- Veröffentlicht 14.02.2006 19:06:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
- Quelle secure@microsoft.com
- Teams Watchlist Login
- Unerledigt Login
Buffer overflow in the plug-in for Microsoft Windows Media Player (WMP) 9 and 10, when used in browsers other than Internet Explorer and set as the default application to handle media files, allows remote attackers to execute arbitrary code via HTML with an EMBED element containing a long src attribute.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Windows-nt Versiondatacenter_server
Microsoft ≫ Windows-nt Versiondatacenter_server Updatesp1
Microsoft ≫ Windows-nt Versiondatacenter_server Updatesp2
Microsoft ≫ Windows-nt Versiondatacenter_server Updatesp3
Microsoft ≫ Windows-nt Versiondatacenter_server Updatesp4
Microsoft ≫ Windows-nt Versionxp Updatesp2 Editionhome
Microsoft ≫ Windows-nt Versionxp_tablet_pc
Microsoft ≫ Windows-nt Versionxp_tablet_pc Updatesp1
Microsoft ≫ Windows-nt Versionxp_tablet_pc Updatesp2
Microsoft ≫ Windows 2000 Updatesp1 Editionpro
Microsoft ≫ Windows 2000 Updatesp2 Editionpro
Microsoft ≫ Windows 2000 Updatesp3 Editionpro
Microsoft ≫ Windows 2000 Updatesp4
Microsoft ≫ Windows 2000 Updatesp4 Editionpro
Microsoft ≫ Windows 2000 Version-
Microsoft ≫ Windows 2000 Advanced Server Versionsp1
Microsoft ≫ Windows 2000 Advanced Server Versionsp2
Microsoft ≫ Windows 2000 Advanced Server Versionsp3
Microsoft ≫ Windows 2000 Advanced Server Versionsp4
Microsoft ≫ Windows 2003 Server Versiondatacenter_edition
Microsoft ≫ Windows 2003 Server Versiondatacenter_edition_64-bit
Microsoft ≫ Windows 2003 Server Versionenterprise_edition
Microsoft ≫ Windows 2003 Server Versionenterprise_edition_64-bit
Microsoft ≫ Windows 2003 Server Versionstandard
Microsoft ≫ Windows 2003 Server Versionstandard_64-bit
Microsoft ≫ Windows 2003 Server Versionweb_edition
Microsoft ≫ Windows Server 2000 Versionnone
Microsoft ≫ Windows Server 2000 Versionsp1
Microsoft ≫ Windows Server 2000 Versionsp2
Microsoft ≫ Windows Server 2000 Versionsp3
Microsoft ≫ Windows Server 2003 Versiondatacenter_sp1
Microsoft ≫ Windows Server 2003 Versionenterprise_sp1
Microsoft ≫ Windows Server 2003 Versionstandard_sp1
Microsoft ≫ Windows Server 2003 Versionweb_edition_sp1
Microsoft ≫ Windows Xp Editionhome
Microsoft ≫ Windows Xp Editionmedia_center
Microsoft ≫ Windows Xp Editionpro
Microsoft ≫ Windows Xp Editionx64
Microsoft ≫ Windows Xp Updatesp1 Editionhome
Microsoft ≫ Windows Xp Updatesp1 Editionmedia_center
Microsoft ≫ Windows Xp Updatesp1 Editionpro
Microsoft ≫ Windows Xp Updatesp2 Editionmedia_center
Microsoft ≫ Windows Xp Updatesp2 Editionpro
Microsoft ≫ Windows Xp Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 82.19% | 0.992 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 9.3 | 8.6 | 10 |
AV:N/AC:M/Au:N/C:C/I:C/A:C
|
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.