9.3

CVE-2006-0020

Exploit
An unspecified Microsoft WMF parsing application, as used in Internet Explorer 5.01 SP4 on Windows 2000 SP4, and 5.5 SP2 on Windows Millennium, and possibly other versions, allows attackers to cause a denial of service (crash) and possibly execute code via a crafted WMF file with a manipulated WMF header size, possibly involving an integer overflow, a different vulnerability than CVE-2005-4560, and aka "WMF Image Parsing Memory Corruption Vulnerability."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Windows 2000 Update sp4 Lang fr
Microsoft ≫ Windows 2003 Server Version sp1
Microsoft ≫ Windows 98 Update gold
Microsoft ≫ Windows Xp Update sp1 Edition tablet_pc
Microsoft ≫ Windows Xp Update sp2 Edition tablet_pc
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 19.06% 0.97
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://linuxbox.org/pipermail/funsec/2006-January/002828.html
Vendor Advisory
Exploit
http://secunia.com/advisories/18729
Patch
Vendor Advisory
http://secunia.com/advisories/18912
Vendor Advisory
http://www.kb.cert.org/vuls/id/312956
Patch
Third Party Advisory
US Government Resource
http://www.microsoft.com/technet/security/advisory/913333.mspx
Vendor Advisory
http://www.osvdb.org/22976
http://www.securityfocus.com/bid/16516
Patch
http://www.us-cert.gov/cas/techalerts/TA06-045A.html
Third Party Advisory
US Government Resource
http://www.vupen.com/english/advisories/2006/0469
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-004
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1638