Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2006-0005 | First vendor Publication | 2006-02-14 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:M/Au:N/C:C/I:C/A:C) | |||
---|---|---|---|
Cvss Base Score | 9.3 | Attack Range | Network |
Cvss Impact Score | 10 | Attack Complexity | Medium |
Cvss Expoit Score | 8.6 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Buffer overflow in the plug-in for Microsoft Windows Media Player (WMP) 9 and 10, when used in browsers other than Internet Explorer and set as the default application to handle media files, allows remote attackers to execute arbitrary code via HTML with an EMBED element containing a long src attribute. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0005 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-119 | Failure to Constrain Operations within the Bounds of a Memory Buffer |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:1559 | |||
Oval ID: | oval:org.mitre.oval:def:1559 | ||
Title: | Windows Media Player Plug-in EMBED Vulnerability | ||
Description: | Buffer overflow in the plug-in for Microsoft Windows Media Player (WMP) 9 and 10, when used in browsers other than Internet Explorer and set as the default application to handle media files, allows remote attackers to execute arbitrary code via HTML with an EMBED element containing a long src attribute. | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2006-0005 | Version: | 5 |
Platform(s): | Microsoft Windows 2000 Microsoft Windows XP Microsoft Windows Server 2003 | Product(s): | Windows Media Player |
Definition Synopsis: | |||
CPE : Common Platform Enumeration
SAINT Exploits
Description | Link |
---|---|
Windows Media Player plugin EMBED buffer overflow | More info here |
ExploitDB Exploits
id | Description |
---|---|
2006-02-17 | MS Windows Media Player 10 Plugin Overflow Exploit (MS06-006) |
2006-02-17 | MS Windows Media Player 9 Plugin Overflow Exploit (MS06-006) (meta) |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
23132 | Microsoft Windows Media Player Plug-in Malformed EMBED Element Arbitrary Code... |
Snort® IPS/IDS
Date | Description |
---|---|
2014-01-10 | Microsoft Windows Media Player Plugin for Non-IE browsers buffer overflow att... RuleID : 5710 - Revision : 17 - Type : OS-WINDOWS |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2006-02-14 | Name : Arbitrary code can be executed on the remote host through Media Player. File : smb_nt_ms06-006.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:21:03 |
|
2024-11-28 12:08:09 |
|
2021-05-04 12:03:35 |
|
2021-04-22 01:04:03 |
|
2020-05-23 00:17:16 |
|
2019-04-30 21:19:19 |
|
2018-10-31 00:19:45 |
|
2018-10-13 00:22:32 |
|
2017-10-11 09:23:36 |
|
2017-07-11 12:02:08 |
|
2016-09-30 01:01:02 |
|
2016-06-28 15:33:06 |
|
2016-04-26 14:10:40 |
|
2014-02-17 10:34:11 |
|
2014-01-19 21:23:02 |
|
2013-05-11 10:45:52 |
|