CVE-2006-6456
high · 9.3Unspecified vulnerability in Microsoft Word 2000, 2002, and 2003 and Word Viewer 2003 allows remote attackers to execute code via unspecified vectors related to malformed data structures that trigger memory corruption, a different vulnerability than CVE-2006-5994.
9.3
CVSS
32.2%
EPSS (exploit prob.)
98th
EPSS percentile
2006-12-11
Published
AV:N/AC:M/Au:N/C:C/I:C/A:C
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| microsoft | office | 2000 |
| microsoft | office | 2003 |
| microsoft | office | 2004 |
| microsoft | office | xp |
| microsoft | word | 2000 |
| microsoft | word | 2002 |
| microsoft | word | 2003 |
| microsoft | word_viewer | 2003 |
| microsoft | works | 2004 |
| microsoft | works | 2005 |
| microsoft | works | 2006 |
Check a specific version with /api/v1/cve/match.
References
- http://archives.neohapsis.com/archives/fulldisclosure/2006-12/0199.html
- http://archives.neohapsis.com/archives/fulldisclosure/2006-12/0215.html
- http://blogs.technet.com/msrc/archive/2006/12/10/new-report-of-a-word-zero-day.aspx
- http://isc.sans.org/diary.php?storyid=1925
- http://secunia.com/advisories/23205
- http://securitytracker.com/id?1017358
- http://securitytracker.com/id?1017579
- http://vil.mcafeesecurity.com/vil/content/v_141056.htm
- http://vil.mcafeesecurity.com/vil/content/v_vul27249.htm
- http://www.kb.cert.org/vuls/id/166700
- http://www.osvdb.org/30825
- http://www.securityfocus.com/archive/1/454069/100/0/threaded
- http://www.securityfocus.com/archive/1/454072/100/0/threaded
- http://www.securityfocus.com/archive/1/454093/100/0/threaded
- http://www.securityfocus.com/bid/21518
- http://www.us-cert.gov/cas/techalerts/TA07-044A.html
- http://www.vupen.com/english/advisories/2006/4920
- http://www.vupen.com/english/advisories/2007/0435
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-014
- https://exchange.xforce.ibmcloud.com/vulnerabilities/30806
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A746
- http://archives.neohapsis.com/archives/fulldisclosure/2006-12/0199.html
- http://archives.neohapsis.com/archives/fulldisclosure/2006-12/0215.html
- http://blogs.technet.com/msrc/archive/2006/12/10/new-report-of-a-word-zero-day.aspx
- http://isc.sans.org/diary.php?storyid=1925
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2006-6456