CVE-2006-0020
 
Severity Score
9.3
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
1
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
An unspecified Microsoft WMF parsing application, as used in Internet Explorer 5.01 SP4 on Windows 2000 SP4, and 5.5 SP2 on Windows Millennium, and possibly other versions, allows attackers to cause a denial of service (crash) and possibly execute code via a crafted WMF file with a manipulated WMF header size, possibly involving an integer overflow, a different vulnerability than CVE-2005-4560, and aka "WMF Image Parsing Memory Corruption Vulnerability."
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2005-11-30 CVE Reserved
- 2006-01-10 CVE Published
- 2024-05-01 EPSS Updated
- 2024-08-07 CVE Updated
- 2024-08-07 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-189: Numeric Errors
CAPEC
References (11)
URL | Tag | Source |
---|---|---|
http://www.osvdb.org/22976 | Vdb Entry | |
http://www.us-cert.gov/cas/techalerts/TA06-045A.html | Third Party Advisory | |
http://www.vupen.com/english/advisories/2006/0469 | Vdb Entry | |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1638 | Signature |
URL | Date | SRC |
---|---|---|
http://linuxbox.org/pipermail/funsec/2006-January/002828.html | 2024-08-07 |
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/18729 | 2018-10-12 | |
http://www.kb.cert.org/vuls/id/312956 | 2018-10-12 | |
http://www.securityfocus.com/bid/16516 | 2018-10-12 |
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/18912 | 2018-10-12 | |
http://www.microsoft.com/technet/security/advisory/913333.mspx | 2018-10-12 | |
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-004 | 2018-10-12 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Microsoft Search vendor "Microsoft" | Windows 2000 Search vendor "Microsoft" for product "Windows 2000" | * | sp4, fr |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows 2003 Server Search vendor "Microsoft" for product "Windows 2003 Server" | r2 Search vendor "Microsoft" for product "Windows 2003 Server" and version "r2" | - |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows 2003 Server Search vendor "Microsoft" for product "Windows 2003 Server" | sp1 Search vendor "Microsoft" for product "Windows 2003 Server" and version "sp1" | - |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows 98 Search vendor "Microsoft" for product "Windows 98" | * | gold |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows 98se Search vendor "Microsoft" for product "Windows 98se" | * | - |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows Me Search vendor "Microsoft" for product "Windows Me" | * | - |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows Xp Search vendor "Microsoft" for product "Windows Xp" | * | sp1, tablet_pc |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows Xp Search vendor "Microsoft" for product "Windows Xp" | * | sp2, tablet_pc |
Affected
|