5.4

CVE-2006-3351

Exploit
Buffer overflow in Windows Explorer (explorer.exe) on Windows XP and 2003 allows user-assisted attackers to cause a denial of service (repeated crash) and possibly execute arbitrary code via a .url file with an InternetShortcut tag containing a long URL and a large number of "file:" specifiers.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Windows 2003 Server Version 3.1.0.3270
Microsoft ≫ Windows 2003 Server Version 64-bit
Microsoft ≫ Windows 2003 Server Version datacenter_64-bit Update sp1
Microsoft ≫ Windows 2003 Server Version datacenter_64-bit Update sp1_beta_1
Microsoft ≫ Windows 2003 Server Version datacenter_edition
Microsoft ≫ Windows 2003 Server Version datacenter_edition Update sp1
Microsoft ≫ Windows 2003 Server Version datacenter_edition Update sp1_beta_1
Microsoft ≫ Windows 2003 Server Version datacenter_edition_64-bit
Microsoft ≫ Windows 2003 Server Version datacenter_edition_64-bit Update sp1
Microsoft ≫ Windows 2003 Server Version datacenter_edition_64-bit Update sp1_beta_1
Microsoft ≫ Windows 2003 Server Version enterprise Edition 64-bit
Microsoft ≫ Windows 2003 Server Version enterprise Update sp1
Microsoft ≫ Windows 2003 Server Version enterprise Update sp1_beta_1
Microsoft ≫ Windows 2003 Server Version enterprise_64-bit
Microsoft ≫ Windows 2003 Server Version enterprise_64-bit Update sp1
Microsoft ≫ Windows 2003 Server Version enterprise_64-bit Update sp1_beta_1
Microsoft ≫ Windows 2003 Server Version enterprise_edition Update sp1
Microsoft ≫ Windows 2003 Server Version enterprise_edition Update sp1_beta_1
Microsoft ≫ Windows 2003 Server Version enterprise_edition_64-bit
Microsoft ≫ Windows 2003 Server Version enterprise_edition_64-bit Update sp1
Microsoft ≫ Windows 2003 Server Version enterprise_edition_64-bit Update sp1_beta_1
Microsoft ≫ Windows 2003 Server Version itanium
Microsoft ≫ Windows 2003 Server Version r2 Edition 64-bit
Microsoft ≫ Windows 2003 Server Version r2 Edition datacenter_64-bit
Microsoft ≫ Windows 2003 Server Version r2 Update sp1
Microsoft ≫ Windows 2003 Server Version r2 Update sp1_beta_1
Microsoft ≫ Windows 2003 Server Version sp1
Microsoft ≫ Windows 2003 Server Version sp1 Edition enterprise
Microsoft ≫ Windows 2003 Server Version sp1 Edition itanium
Microsoft ≫ Windows 2003 Server Version standard
Microsoft ≫ Windows 2003 Server Version standard Edition 64-bit
Microsoft ≫ Windows 2003 Server Version standard Update sp1
Microsoft ≫ Windows 2003 Server Version standard Update sp1_beta_1
Microsoft ≫ Windows 2003 Server Version standard_64-bit
Microsoft ≫ Windows 2003 Server Version web
Microsoft ≫ Windows 2003 Server Version web Update sp1
Microsoft ≫ Windows 2003 Server Version web Update sp1_beta_1
Microsoft ≫ Windows Xp Edition 64-bit
Microsoft ≫ Windows Xp Edition embedded
Microsoft ≫ Windows Xp Edition home
Microsoft ≫ Windows Xp Edition media_center
Microsoft ≫ Windows Xp Update gold
Microsoft ≫ Windows Xp Update gold Edition home
Microsoft ≫ Windows Xp Update gold Edition professional
Microsoft ≫ Windows Xp Update sp1 Edition 64-bit
Microsoft ≫ Windows Xp Update sp1 Edition embedded
Microsoft ≫ Windows Xp Update sp1 Edition home
Microsoft ≫ Windows Xp Update sp1 Edition media_center
Microsoft ≫ Windows Xp Update sp1 Edition tablet_pc
Microsoft ≫ Windows Xp Update sp2 Edition home
Microsoft ≫ Windows Xp Update sp2 Edition media_center
Microsoft ≫ Windows Xp Update sp2 Edition tablet_pc
Microsoft ≫ Windows Xp Version ibm_oem_version
Microsoft ≫ Windows Xp Version ibm_oem_version Update sp1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 6.93% 0.933
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.4 4.9 6.9
AV:N/AC:H/Au:N/C:N/I:N/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://securityreason.com/securityalert/1186
http://www.securityfocus.com/archive/1/439153/100/0/threaded
http://www.securityfocus.com/archive/1/439660/100/200/threaded
http://www.securityfocus.com/bid/18838
Exploit
https://exchange.xforce.ibmcloud.com/vulnerabilities/27567