Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2006-3730 | First vendor Publication | 2006-07-21 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:M/Au:N/C:C/I:C/A:C) | |||
---|---|---|---|
Cvss Base Score | 9.3 | Attack Range | Network |
Cvss Impact Score | 10 | Attack Complexity | Medium |
Cvss Expoit Score | 8.6 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Integer overflow in Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a 0x7fffffff argument to the setSlice method on a WebViewFolderIcon ActiveX object, which leads to an invalid memory copy. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3730 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-94 | Failure to Control Generation of Code ('Code Injection') |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:339 | |||
Oval ID: | oval:org.mitre.oval:def:339 | ||
Title: | Windows Shell Remote Code Execution Vulnerability | ||
Description: | Integer overflow in Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a 0x7fffffff argument to the setSlice method on a WebViewFolderIcon ActiveX object, which leads to an invalid memory copy. | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2006-3730 | Version: | 3 |
Platform(s): | Microsoft Windows 2000 Microsoft Windows XP Microsoft Windows Server 2003 | Product(s): | |
Definition Synopsis: | |||
|
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Application | 1 | |
Application | 1 |
SAINT Exploits
Description | Link |
---|---|
Internet Explorer WebViewFolderIcon setSlice integer overflow | More info here |
ExploitDB Exploits
id | Description |
---|---|
2010-07-03 | Internet Explorer WebViewFolderIcon setSlice() Overflow |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
27110 | Microsoft IE WebViewFolderIcon setSlice Overflow Internet Explorer contains a flaw that may allow a remote denial of service. The issue is triggered when calling the 'setSlice' method of the WebViewFolderIcon.WebViewFolderIcon.1 ActiveX object with the first parameter set to 0x7fffffff. This causes an invalid memory copy and may result in arbitrary code execution and/or a loss of availability for the browser. |
Information Assurance Vulnerability Management (IAVM)
Date | Description |
---|---|
2006-10-13 | IAVM : 2006-A-0042 - Vulnerability in Windows Explorer Severity : Category I - VMSKEY : V0012782 |
Snort® IPS/IDS
Date | Description |
---|---|
2014-01-10 | Microsoft Windows Explorer WebViewFolderIcon.WebViewFolderIcon.1 ActiveX func... RuleID : 8419 - Revision : 19 - Type : BROWSER-PLUGINS |
2014-01-10 | WebViewFolderIcon.WebViewFolderIcon.1 ActiveX CLSID unicode access RuleID : 7986 - Revision : 9 - Type : WEB-ACTIVEX |
2014-01-10 | Microsoft Windows Explorer WebViewFolderIcon.WebViewFolderIcon.1 ActiveX clsi... RuleID : 7985 - Revision : 18 - Type : BROWSER-PLUGINS |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2006-10-10 | Name : Arbitrary code can be executed on the remote host through the web or email cl... File : smb_nt_ms06-057.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:19:58 |
|
2024-11-28 12:09:32 |
|
2021-07-27 00:24:35 |
|
2021-07-24 01:44:13 |
|
2021-07-24 01:02:46 |
|
2021-07-23 17:24:39 |
|
2020-05-23 13:16:47 |
|
2020-05-23 00:18:07 |
|
2019-03-18 12:01:23 |
|
2018-10-18 00:19:35 |
|
2018-10-13 00:22:35 |
|
2017-10-19 09:23:49 |
|
2017-10-11 09:23:43 |
|
2017-07-20 09:23:46 |
|
2016-06-28 15:53:09 |
|
2016-04-26 14:53:00 |
|
2014-02-17 10:36:35 |
|
2014-01-19 21:23:25 |
|
2013-11-11 12:37:37 |
|
2013-05-11 11:03:50 |
|