← All CVEs

CVE-2006-1900

high · 7.6

Multiple buffer overflows in World Wide Web Consortium (W3C) Amaya 9.4, and possibly other versions including 8.x before 8.8.5, allow remote attackers to execute arbitrary code via a long value in (1) the COMPACT attribute of the COLGROUP element, (2) the ROWS attribute of the TEXTAREA element, and (3) the COLOR attribute of the LEGEND element; and via other unspecified attack vectors consisting of "dozens of possible snippets."

7.6
CVSS
16.5%
EPSS (exploit prob.)
97th
EPSS percentile
2006-04-20
Published

AV:N/AC:H/Au:N/C:C/I:C/A:C

Affected products

VendorProductAffected versions
w3camaya9.4

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2006-1900