5.4

CVE-2006-3351

Exploit

Buffer overflow in Windows Explorer (explorer.exe) on Windows XP and 2003 allows user-assisted attackers to cause a denial of service (repeated crash) and possibly execute arbitrary code via a .url file with an InternetShortcut tag containing a long URL and a large number of "file:" specifiers.

Data is provided by the National Vulnerability Database (NVD)
MicrosoftWindows 2003 Server Version3.1.0.3270
MicrosoftWindows 2003 Server Version64-bit
MicrosoftWindows 2003 Server Versiondatacenter_64-bit Updatesp1
MicrosoftWindows 2003 Server Versiondatacenter_64-bit Updatesp1_beta_1
MicrosoftWindows 2003 Server Versiondatacenter_edition
MicrosoftWindows 2003 Server Versiondatacenter_edition Updatesp1
MicrosoftWindows 2003 Server Versiondatacenter_edition Updatesp1_beta_1
MicrosoftWindows 2003 Server Versiondatacenter_edition_64-bit
MicrosoftWindows 2003 Server Versiondatacenter_edition_64-bit Updatesp1
MicrosoftWindows 2003 Server Versiondatacenter_edition_64-bit Updatesp1_beta_1
MicrosoftWindows 2003 Server Versionenterprise Edition64-bit
MicrosoftWindows 2003 Server Versionenterprise Updatesp1
MicrosoftWindows 2003 Server Versionenterprise Updatesp1_beta_1
MicrosoftWindows 2003 Server Versionenterprise_64-bit
MicrosoftWindows 2003 Server Versionenterprise_64-bit Updatesp1
MicrosoftWindows 2003 Server Versionenterprise_64-bit Updatesp1_beta_1
MicrosoftWindows 2003 Server Versionenterprise_edition Updatesp1
MicrosoftWindows 2003 Server Versionenterprise_edition Updatesp1_beta_1
MicrosoftWindows 2003 Server Versionenterprise_edition_64-bit
MicrosoftWindows 2003 Server Versionenterprise_edition_64-bit Updatesp1
MicrosoftWindows 2003 Server Versionenterprise_edition_64-bit Updatesp1_beta_1
MicrosoftWindows 2003 Server Versionitanium
MicrosoftWindows 2003 Server Versionr2 Edition64-bit
MicrosoftWindows 2003 Server Versionr2 Editiondatacenter_64-bit
MicrosoftWindows 2003 Server Versionr2 Updatesp1
MicrosoftWindows 2003 Server Versionr2 Updatesp1_beta_1
MicrosoftWindows 2003 Server Versionsp1 Editionenterprise
MicrosoftWindows 2003 Server Versionsp1 Editionitanium
MicrosoftWindows 2003 Server Versionstandard
MicrosoftWindows 2003 Server Versionstandard Edition64-bit
MicrosoftWindows 2003 Server Versionstandard Updatesp1
MicrosoftWindows 2003 Server Versionstandard Updatesp1_beta_1
MicrosoftWindows 2003 Server Versionstandard_64-bit
MicrosoftWindows 2003 Server Versionweb Updatesp1
MicrosoftWindows 2003 Server Versionweb Updatesp1_beta_1
MicrosoftWindows Xp Edition64-bit
MicrosoftWindows Xp Editionembedded
MicrosoftWindows Xp Editionhome
MicrosoftWindows Xp Editionmedia_center
MicrosoftWindows Xp Updategold
MicrosoftWindows Xp Updategold Editionhome
MicrosoftWindows Xp Updategold Editionprofessional
MicrosoftWindows Xp Updatesp1 Edition64-bit
MicrosoftWindows Xp Updatesp1 Editionembedded
MicrosoftWindows Xp Updatesp1 Editionhome
MicrosoftWindows Xp Updatesp1 Editionmedia_center
MicrosoftWindows Xp Updatesp1 Editiontablet_pc
MicrosoftWindows Xp Updatesp2 Editionhome
MicrosoftWindows Xp Updatesp2 Editionmedia_center
MicrosoftWindows Xp Updatesp2 Editiontablet_pc
MicrosoftWindows Xp Versionibm_oem_version
MicrosoftWindows Xp Versionibm_oem_version Updatesp1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 25.5% 0.957
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5.4 4.9 6.9
AV:N/AC:H/Au:N/C:N/I:N/A:C