7.6

CVE-2006-1900

Exploit
Multiple buffer overflows in World Wide Web Consortium (W3C) Amaya 9.4, and possibly other versions including 8.x before 8.8.5, allow remote attackers to execute arbitrary code via a long value in (1) the COMPACT attribute of the COLGROUP element, (2) the ROWS attribute of the TEXTAREA element, and (3) the COLOR attribute of the LEGEND element; and via other unspecified attack vectors consisting of "dozens of possible snippets."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
W3cAmaya Version9.4
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 16.55% 0.966
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.6 4.9 10
AV:N/AC:H/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://morph3us.org/advisories/20060412-amaya-94-2.txt
Vendor Advisory
Exploit
http://morph3us.org/advisories/20060412-amaya-94.txt
Vendor Advisory
Exploit
http://secunia.com/advisories/19670
Patch
Vendor Advisory
http://www.osvdb.org/24623
Patch
http://www.osvdb.org/24624
Patch
http://www.securityfocus.com/archive/1/430877/100/0/threaded
http://www.securityfocus.com/archive/1/430879/100/0/threaded
http://www.securityfocus.com/bid/17507
Exploit
http://www.vupen.com/english/advisories/2006/1351
https://exchange.xforce.ibmcloud.com/vulnerabilities/25791