Lucene search

K
nvd[email protected]NVD:CVE-2006-3647
HistoryOct 10, 2006 - 10:07 p.m.

CVE-2006-3647

2006-10-1022:07:00
CWE-189
web.nvd.nist.gov
1

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.5 High

AI Score

Confidence

Low

0.621 Medium

EPSS

Percentile

97.8%

Integer overflow in Microsoft Word 2000, 2002, 2003, 2004 for Mac, and v.X for Mac allows remote user-assisted attackers to execute arbitrary code via a crafted string in a Word document, which overflows a 16-bit integer length value, aka “Memmove Code Execution,” a different vulnerability than CVE-2006-3651 and CVE-2006-4693.

Affected configurations

NVD
Node
microsoftofficeMatch2000
OR
microsoftofficeMatch2000ja
OR
microsoftofficeMatch2000ko
OR
microsoftofficeMatch2000zh
OR
microsoftofficeMatch2000sp1
OR
microsoftofficeMatch2000sp2
OR
microsoftofficeMatch2000sp3
OR
microsoftofficeMatch2001
OR
microsoftofficeMatch2001mac_os_x
OR
microsoftofficeMatch2001sr1mac_os_x
OR
microsoftofficeMatch2003student_teacher
OR
microsoftofficeMatch2003sp1
OR
microsoftofficeMatch2003sp2
OR
microsoftofficeMatch2003sp3
OR
microsoftofficeMatch2004mac_os_x
OR
microsoftofficeMatchv.x

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.5 High

AI Score

Confidence

Low

0.621 Medium

EPSS

Percentile

97.8%

Related for NVD:CVE-2006-3647