← All CVEs

CVE-2006-3014

medium · 5.1

Microsoft Excel allows user-assisted attackers to execute arbitrary javascript and redirect users to arbitrary sites via an Excel spreadsheet with an embedded Shockwave Flash Player ActiveX Object, which is automatically executed when the user opens the spreadsheet.

5.1
CVSS
30.1%
EPSS (exploit prob.)
98th
EPSS percentile
2006-06-22
Published

AV:N/AC:H/Au:N/C:P/I:P/A:P

Weaknesses

CWE-20

Affected products

VendorProductAffected versions
microsoftexcelall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2006-3014