CVE-2006-4494
high · 7.5Microsoft Visual Studio 6.0 allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code by instantiating certain Visual Studio 6.0 ActiveX COM Objects in Internet Explorer, including (1) tcprops.dll, (2) fp30wec.dll, (3) mdt2db.dll, (4) mdt2qd.dll, and (5) vi30aut.dll.
7.5
CVSS
22.1%
EPSS (exploit prob.)
98th
EPSS percentile
2006-08-31
Published
AV:N/AC:L/Au:N/C:P/I:P/A:P
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| microsoft | visual_studio | 6.0 |
| microsoft | visual_studio | 6.0 |
Check a specific version with /api/v1/cve/match.
References
- http://securityreason.com/securityalert/1473
- http://www.securityfocus.com/archive/1/443499/100/100/threaded
- http://www.securityfocus.com/bid/19572
- http://www.xsec.org/index.php?module=releases&act=view&type=1&id=15
- http://securityreason.com/securityalert/1473
- http://www.securityfocus.com/archive/1/443499/100/100/threaded
- http://www.securityfocus.com/bid/19572
- http://www.xsec.org/index.php?module=releases&act=view&type=1&id=15
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2006-4494