5.1
CVE-2006-2910
- EPSS 2.12%
- Veröffentlicht 05.07.2006 18:05:00
- Zuletzt bearbeitet 23.09.2026 13:10:00
- Erkennungen
Buffer overflow in jetAudio 6.2.6.8330 (Basic), and possibly other versions, allows user-assisted attackers to execute arbitrary code via an audio file (such as WMA) with long ID Tag values including (1) Title, (2) Author, and (3) Album, which triggers the overflow in the tooltip display string if the sound card driver is disabled or incorrectly installed.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cowon America ≫ Jetaudio Version basic_6.2.6.8330
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.12% | 0.8 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5.1 | 4.9 | 6.4 |
AV:N/AC:H/Au:N/C:P/I:P/A:P
|
http://secunia.com/advisories/19456
http://secunia.com/secunia_research/2006-45/advisory/
http://www.securityfocus.com/bid/18825
http://www.vupen.com/english/advisories/2006/2667
https://exchange.xforce.ibmcloud.com/vulnerabilities/27593