Lucene search

K
cve[email protected]CVE-2006-5994
HistoryDec 06, 2006 - 8:28 p.m.

CVE-2006-5994

2006-12-0620:28:00
web.nvd.nist.gov
47
microsoft word
office word
word viewer
remote code execution
memory corruption
cve-2006-5994
security vulnerability

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.3 High

AI Score

Confidence

Low

0.961 High

EPSS

Percentile

99.5%

Unspecified vulnerability in Microsoft Word 2000 and 2002, Office Word and Word Viewer 2003, Word 2004 and 2004 v. X for Mac, and Works 2004, 2005, and 2006 allows remote attackers to execute arbitrary code via a Word document with a malformed string that triggers memory corruption, a different vulnerability than CVE-2006-6456.

Affected configurations

NVD
Node
microsoftofficeMatch2000sp3
OR
microsoftofficeMatch2003sp2
OR
microsoftofficeMatch2004mac
OR
microsoftofficeMatchxpsp3
OR
microsoftwordMatch2000
OR
microsoftwordMatch2002
OR
microsoftwordMatch2003
OR
microsoftword_viewerMatch2003
OR
microsoftworksMatch2004
OR
microsoftworksMatch2005
OR
microsoftworksMatch2006

References

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.3 High

AI Score

Confidence

Low

0.961 High

EPSS

Percentile

99.5%