9.3

CVE-2006-4868

Exploit
Stack-based buffer overflow in the Vector Graphics Rendering engine (vgx.dll), as used in Microsoft Outlook and Internet Explorer 6.0 on Windows XP SP2, and possibly other versions, allows remote attackers to execute arbitrary code via a Vector Markup Language (VML) file with a long fill parameter within a rect tag.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Internet Explorer Version 6.0
   Microsoft ≫ Windows 2000 Update sp4
   Microsoft ≫ Windows 2003 Server
   Microsoft ≫ Windows 2003 Server Edition itanium
   Microsoft ≫ Windows 2003 Server Edition x64
   Microsoft ≫ Windows 2003 Server Update gold
   Microsoft ≫ Windows 2003 Server Update sp1
   Microsoft ≫ Windows Xp
   Microsoft ≫ Windows Xp Update sp1
   Microsoft ≫ Windows Xp Update sp2
Microsoft ≫ Outlook Version 2003
   Microsoft ≫ Windows 2000 Update sp4
   Microsoft ≫ Windows 2003 Server
   Microsoft ≫ Windows 2003 Server Edition itanium
   Microsoft ≫ Windows 2003 Server Edition x64
   Microsoft ≫ Windows 2003 Server Update gold
   Microsoft ≫ Windows 2003 Server Update sp1
   Microsoft ≫ Windows Xp
   Microsoft ≫ Windows Xp Update sp1
   Microsoft ≫ Windows Xp Update sp2
Microsoft ≫ Internet Explorer Version 5.0.1 Update sp4
   Microsoft ≫ Windows 2000 Update sp4
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 61.44% 0.991
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

http://blogs.securiteam.com/index.php/archives/624
http://secunia.com/advisories/21989
Patch
Vendor Advisory
http://securitytracker.com/id?1016879
http://sunbeltblog.blogspot.com/2006/09/seen-in-wild-zero-day-exploit-being.html
http://support.microsoft.com/kb/925486
http://www.kb.cert.org/vuls/id/416092
US Government Resource
http://www.microsoft.com/technet/security/advisory/925568.mspx
Patch
Vendor Advisory
http://www.osvdb.org/28946
http://www.securityfocus.com/archive/1/446378/100/0/threaded
http://www.securityfocus.com/archive/1/446505/100/0/threaded
http://www.securityfocus.com/archive/1/446523/100/0/threaded
http://www.securityfocus.com/archive/1/446528/100/0/threaded
http://www.securityfocus.com/archive/1/446881/100/200/threaded
http://www.securityfocus.com/archive/1/447070/100/0/threaded
http://www.securityfocus.com/archive/1/448552/100/0/threaded
http://www.securityfocus.com/bid/20096
Patch
Exploit
http://www.us-cert.gov/cas/techalerts/TA06-262A.html
Patch
US Government Resource
http://www.vupen.com/english/advisories/2006/3679
Vendor Advisory
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-055
https://exchange.xforce.ibmcloud.com/vulnerabilities/29004
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100