// For flags

CVE-2006-0009

 

Severity Score

5.1
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Buffer overflow in Microsoft Office 2000 SP3, XP SP3, and other versions and packages, allows user-assisted attackers to execute arbitrary code via a routing slip that is longer than specified by the provided length field, as exploited by malware such as TROJ_MDROPPER.BH and Trojan.PPDropper.E in attacks against PowerPoint.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
High
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2005-11-09 CVE Reserved
  • 2006-03-14 CVE Published
  • 2024-07-03 EPSS Updated
  • 2024-08-07 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
CAPEC
References (36)
URL Tag Source
http://archives.neohapsis.com/archives/fulldisclosure/2006-08/0597.html Mailing List
http://blogs.securiteam.com/?author=28 X_refsource_misc
http://blogs.securiteam.com/?p=557 X_refsource_misc
http://blogs.securiteam.com/?p=559 X_refsource_misc
http://isc.sans.org/diary.php?storyid=1618 X_refsource_misc
http://lists.grok.org.uk/pipermail/full-disclosure/2006-September/049540.html Mailing List
http://secunia.com/advisories/19238 Third Party Advisory
http://securitytracker.com/id?1016720 Vdb Entry
http://securitytracker.com/id?1016886 Vdb Entry
http://support.avaya.com/elmodocs2/security/ASA-2006-069.htm X_refsource_confirm
http://www.darkreading.com/document.asp?doc_id=101970 X_refsource_misc
http://www.kb.cert.org/vuls/id/682820 Third Party Advisory
http://www.osvdb.org/23903 Vdb Entry
http://www.securityfocus.com/archive/1/427671/100/0/threaded Mailing List
http://www.securityfocus.com/archive/1/432004/30/5340/threaded Mailing List
http://www.securityfocus.com/archive/1/443890/100/0/threaded Mailing List
http://www.securityfocus.com/archive/1/444051/100/200/threaded Mailing List
http://www.securityfocus.com/archive/1/446370/100/0/threaded Mailing List
http://www.securityfocus.com/archive/1/446425/100/0/threaded Mailing List
http://www.securityfocus.com/bid/20059 Vdb Entry
http://www.symantec.com/enterprise/research/SYMSA-2006-001.txt X_refsource_misc
http://www.symantec.com/security_response/writeup.jsp?docid=2006-091810-5028-99 X_refsource_misc
http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_MDROPPER.BH X_refsource_misc
http://www.us-cert.gov/cas/techalerts/TA06-073A.html Third Party Advisory
http://www.vupen.com/english/advisories/2006/0950 Vdb Entry
http://www.vupen.com/english/advisories/2006/3678 Vdb Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/25009 Vdb Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/29009 Vdb Entry
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1504 Signature
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1553 Signature
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1653 Signature
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A798 Signature
URL Date SRC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Microsoft
Search vendor "Microsoft"
Office
Search vendor "Microsoft" for product "Office"
2000
Search vendor "Microsoft" for product "Office" and version "2000"
sp3
Affected
Microsoft
Search vendor "Microsoft"
Office
Search vendor "Microsoft" for product "Office"
2003
Search vendor "Microsoft" for product "Office" and version "2003"
sp1
Affected
Microsoft
Search vendor "Microsoft"
Office
Search vendor "Microsoft" for product "Office"
2003
Search vendor "Microsoft" for product "Office" and version "2003"
sp2
Affected
Microsoft
Search vendor "Microsoft"
Office
Search vendor "Microsoft" for product "Office"
2004
Search vendor "Microsoft" for product "Office" and version "2004"
mac
Affected
Microsoft
Search vendor "Microsoft"
Office
Search vendor "Microsoft" for product "Office"
v.x
Search vendor "Microsoft" for product "Office" and version "v.x"
mac
Affected
Microsoft
Search vendor "Microsoft"
Office
Search vendor "Microsoft" for product "Office"
xp
Search vendor "Microsoft" for product "Office" and version "xp"
sp3
Affected
Microsoft
Search vendor "Microsoft"
Works
Search vendor "Microsoft" for product "Works"
2000
Search vendor "Microsoft" for product "Works" and version "2000"
-
Affected
Microsoft
Search vendor "Microsoft"
Works
Search vendor "Microsoft" for product "Works"
2001
Search vendor "Microsoft" for product "Works" and version "2001"
-
Affected
Microsoft
Search vendor "Microsoft"
Works
Search vendor "Microsoft" for product "Works"
2002
Search vendor "Microsoft" for product "Works" and version "2002"
-
Affected
Microsoft
Search vendor "Microsoft"
Works
Search vendor "Microsoft" for product "Works"
2003
Search vendor "Microsoft" for product "Works" and version "2003"
-
Affected
Microsoft
Search vendor "Microsoft"
Works
Search vendor "Microsoft" for product "Works"
2004
Search vendor "Microsoft" for product "Works" and version "2004"
-
Affected
Microsoft
Search vendor "Microsoft"
Works
Search vendor "Microsoft" for product "Works"
2005
Search vendor "Microsoft" for product "Works" and version "2005"
-
Affected
Microsoft
Search vendor "Microsoft"
Works
Search vendor "Microsoft" for product "Works"
2006
Search vendor "Microsoft" for product "Works" and version "2006"
-
Affected