← All CVEs

CVE-2006-5559

high · 9.3

The Execute method in the ADODB.Connection 2.7 and 2.8 ActiveX control objects (ADODB.Connection.2.7 and ADODB.Connection.2.8) in the Microsoft Data Access Components (MDAC) 2.5 SP3, 2.7 SP1, 2.8, and 2.8 SP1 does not properly track freed memory when the second argument is a BSTR, which allows remote attackers to cause a denial of service (Internet Explorer crash) and possibly execute arbitrary code via certain strings in the second and third arguments.

9.3
CVSS
41.9%
EPSS (exploit prob.)
99th
EPSS percentile
2006-10-27
Published

AV:N/AC:M/Au:N/C:C/I:C/A:C

Weaknesses

CWE-20

Affected products

VendorProductAffected versions
microsoftwindows_2000all versions
microsoftdata_access_components2.5
microsoftwindows_xpall versions
microsoftdata_access_components2.8
microsoftwindows_2003_serverall versions
microsoftwindows_2003_serveritanium
microsoftdata_access_components2.8
microsoftwindows_2000all versions
microsoftdata_access_components2.7
microsoftwindows_2000all versions
microsoftdata_access_components2.8
microsoftwindows_2000all versions
microsoftdata_access_components2.8

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2006-5559