CVE-2006-0020
high · 9.3An unspecified Microsoft WMF parsing application, as used in Internet Explorer 5.01 SP4 on Windows 2000 SP4, and 5.5 SP2 on Windows Millennium, and possibly other versions, allows attackers to cause a denial of service (crash) and possibly execute code via a crafted WMF file with a manipulated WMF header size, possibly involving an integer overflow, a different vulnerability than CVE-2005-4560, and aka "WMF Image Parsing Memory Corruption Vulnerability."
9.3
CVSS
19.1%
EPSS (exploit prob.)
97th
EPSS percentile
2006-01-10
Published
AV:N/AC:M/Au:N/C:C/I:C/A:C
Weaknesses
CWE-189
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| microsoft | windows_2000 | all versions |
| microsoft | windows_2003_server | r2 |
| microsoft | windows_2003_server | sp1 |
| microsoft | windows_98 | all versions |
| microsoft | windows_98se | all versions |
| microsoft | windows_me | all versions |
| microsoft | windows_xp | all versions |
| microsoft | windows_xp | all versions |
Check a specific version with /api/v1/cve/match.
References
- http://linuxbox.org/pipermail/funsec/2006-January/002828.html
- http://secunia.com/advisories/18729
- http://secunia.com/advisories/18912
- http://www.kb.cert.org/vuls/id/312956
- http://www.microsoft.com/technet/security/advisory/913333.mspx
- http://www.osvdb.org/22976
- http://www.securityfocus.com/bid/16516
- http://www.us-cert.gov/cas/techalerts/TA06-045A.html
- http://www.vupen.com/english/advisories/2006/0469
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-004
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1638
- http://linuxbox.org/pipermail/funsec/2006-January/002828.html
- http://secunia.com/advisories/18729
- http://secunia.com/advisories/18912
- http://www.kb.cert.org/vuls/id/312956
- http://www.microsoft.com/technet/security/advisory/913333.mspx
- http://www.osvdb.org/22976
- http://www.securityfocus.com/bid/16516
- http://www.us-cert.gov/cas/techalerts/TA06-045A.html
- http://www.vupen.com/english/advisories/2006/0469
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-004
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1638
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2006-0020