Executive Summary
Informations | |||
---|---|---|---|
Name | MS06-046 | First vendor Publication | N/A |
Vendor | Microsoft | Last vendor Modification | N/A |
Severity (Vendor) | N/A | Revision | N/A |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:P/I:P/A:P) | |||
---|---|---|---|
Cvss Base Score | 7.5 | Attack Range | Network |
Cvss Impact Score | 6.4 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Vulnerability in HTML Help Could Allow Remote Code Execution (922616) |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:13 | |||
Oval ID: | oval:org.mitre.oval:def:13 | ||
Title: | Buffer Overrun in HTML Help Vulnerability | ||
Description: | Heap-based buffer overflow in HTML Help ActiveX control (hhctrl.ocx) in Microsoft Internet Explorer 6.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code by repeatedly setting the Image field of an Internet.HHCtrl.1 object to certain values, possibly related to improper escaping and long strings. | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2006-3357 | Version: | 3 |
Platform(s): | Microsoft Windows 2000 Microsoft Windows XP Microsoft Windows Server 2003 | Product(s): | |
Definition Synopsis: | |||
|
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Application | 1 |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
28134 | Windows NT FTP Server (WFTP) Server SIZE Command Remote Overflow A remote overflow exists in WFTPD. The product fails to perform correct boundary checks on "SIZE" commands, resulting in a buffer overflow. With a specially crafted request, an attacker can cause arbitrary code execution resulting in a loss of integrity. |
26835 | Microsoft IE HTML Help COM Object Image Property Heap Overflow |
Snort® IPS/IDS
Date | Description |
---|---|
2014-01-10 | HTML Help ActiveX clsid unicode access RuleID : 7440 - Revision : 8 - Type : WEB-ACTIVEX |
2014-01-10 | Microsoft Internet Explorer HTML Help ActiveX clsid access RuleID : 7439 - Revision : 16 - Type : BROWSER-PLUGINS |
2014-01-10 | Microsoft Windows Internet.HHCtrl.1 ActiveX function call access RuleID : 7004 - Revision : 20 - Type : BROWSER-PLUGINS |
2014-01-10 | Microsoft Windows help file download request RuleID : 17407 - Revision : 22 - Type : FILE-IDENTIFY |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2006-08-08 | Name : Arbitrary code can be executed on the remote host through the web client. File : smb_nt_ms06-046.nasl - Type : ACT_GATHER_INFO |
Alert History
Date | Informations |
---|---|
2014-02-17 11:45:27 |
|
2014-01-19 21:30:00 |
|