Lucene search

K
cve[email protected]CVE-2008-5823
HistoryJan 02, 2009 - 7:30 p.m.

CVE-2008-5823

2009-01-0219:30:01
CWE-189
web.nvd.nist.gov
19
cve-2008-5823
activex
prtstb06.dll
microsoft money 2006
denial of service
wscript
windows script host
wsh
access violation
application crash
zero value
startup property

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

6.8 Medium

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

68.1%

An ActiveX control in prtstb06.dll in Microsoft Money 2006, when used with WScript in Windows Script Host (WSH) on Windows Vista, allows remote attackers to cause a denial of service (access violation and application crash) via a zero value for the Startup property.

Affected configurations

NVD
Node
microsoftmoneyMatch2006
AND
microsoftwindows_vistaMatch-
OR
microsoftwindows_vistaMatch-sp1
CPENameOperatorVersion
microsoft:moneymicrosoft moneyeq2006

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

6.8 Medium

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

68.1%

Related for CVE-2008-5823