← All CVEs

CVE-2006-0020

high · 9.3

An unspecified Microsoft WMF parsing application, as used in Internet Explorer 5.01 SP4 on Windows 2000 SP4, and 5.5 SP2 on Windows Millennium, and possibly other versions, allows attackers to cause a denial of service (crash) and possibly execute code via a crafted WMF file with a manipulated WMF header size, possibly involving an integer overflow, a different vulnerability than CVE-2005-4560, and aka "WMF Image Parsing Memory Corruption Vulnerability."

9.3
CVSS
19.1%
EPSS (exploit prob.)
97th
EPSS percentile
2006-01-10
Published

AV:N/AC:M/Au:N/C:C/I:C/A:C

Weaknesses

CWE-189

Affected products

VendorProductAffected versions
microsoftwindows_2000all versions
microsoftwindows_2003_serverr2
microsoftwindows_2003_serversp1
microsoftwindows_98all versions
microsoftwindows_98seall versions
microsoftwindows_meall versions
microsoftwindows_xpall versions
microsoftwindows_xpall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2006-0020