Lucene search

K
cve[email protected]CVE-2006-4868
HistorySep 19, 2006 - 7:07 p.m.

CVE-2006-4868

2006-09-1919:07:00
CWE-119
web.nvd.nist.gov
34
cve-2006-4868
stack-based buffer overflow
vector graphics rendering engine
vgx.dll
microsoft outlook
internet explorer 6.0
windows xp sp2
remote code execution
vml file

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.7 High

AI Score

Confidence

Low

0.18 Low

EPSS

Percentile

96.2%

Stack-based buffer overflow in the Vector Graphics Rendering engine (vgx.dll), as used in Microsoft Outlook and Internet Explorer 6.0 on Windows XP SP2, and possibly other versions, allows remote attackers to execute arbitrary code via a Vector Markup Language (VML) file with a long fill parameter within a rect tag.

Affected configurations

NVD
Node
microsoftwindows_2000sp4
OR
microsoftwindows_2003_server
OR
microsoftwindows_2003_serveritanium
OR
microsoftwindows_2003_serverx64
OR
microsoftwindows_2003_servergold
OR
microsoftwindows_2003_serversp1
OR
microsoftwindows_xp
OR
microsoftwindows_xpsp1
OR
microsoftwindows_xpsp2
AND
microsoftinternet_explorerMatch6.0
OR
microsoftoutlookMatch2003
Node
microsoftwindows_2000sp4
AND
microsoftinternet_explorerMatch5.0.1sp4

References

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.7 High

AI Score

Confidence

Low

0.18 Low

EPSS

Percentile

96.2%