Lucene search

K
cve[email protected]CVE-2006-6603
HistoryDec 15, 2006 - 10:28 p.m.

CVE-2006-6603

2006-12-1522:28:00
web.nvd.nist.gov
23
cve-2006-6603
buffer overflow
yahoo! messenger
activex control
remote code execution

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.7 High

AI Score

Confidence

High

0.079 Low

EPSS

Percentile

94.3%

Buffer overflow in the YMMAPI.YMailAttach ActiveX control (ymmapi.dll) before 2005.1.1.4 in Yahoo! Messenger allows remote attackers to execute arbitrary code via a crafted HTML document. NOTE: some details were obtained from third party information.

Affected configurations

NVD
Node
yahoomessengerRange8.0
OR
yahoomessengerMatch5.0
OR
yahoomessengerMatch5.5
OR
yahoomessengerMatch5.6
OR
yahoomessengerMatch6.0
OR
yahoomessengerMatch7.0
OR
yahoomessengerMatch7.5

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.7 High

AI Score

Confidence

High

0.079 Low

EPSS

Percentile

94.3%