Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2006-0005

Опубликовано: 14 фев. 2006
Источник: nvd
CVSS2: 9.3
EPSS Высокий

Описание

Buffer overflow in the plug-in for Microsoft Windows Media Player (WMP) 9 and 10, when used in browsers other than Internet Explorer and set as the default application to handle media files, allows remote attackers to execute arbitrary code via HTML with an EMBED element containing a long src attribute.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:o:microsoft:windows-nt:datacenter_server:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows-nt:datacenter_server:sp1:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows-nt:datacenter_server:sp2:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows-nt:datacenter_server:sp3:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows-nt:datacenter_server:sp4:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows-nt:xp:sp2:home:*:*:*:*:*
cpe:2.3:o:microsoft:windows-nt:xp_tablet_pc:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows-nt:xp_tablet_pc:sp1:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows-nt:xp_tablet_pc:sp2:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2000:*:sp1:pro:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2000:*:sp2:pro:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2000:*:sp3:pro:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2000:*:sp4:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2000:*:sp4:pro:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2000:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2000_advanced_server:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2000_advanced_server:sp1:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2000_advanced_server:sp2:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2000_advanced_server:sp3:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2000_advanced_server:sp4:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2003_server:datacenter_edition:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2003_server:datacenter_edition_64-bit:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2003_server:enterprise_edition:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2003_server:enterprise_edition_64-bit:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2003_server:standard:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2003_server:standard_64-bit:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2003_server:web_edition:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2000:none:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2000:sp1:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2000:sp2:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2000:sp3:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2003:datacenter_sp1:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2003:enterprise_sp1:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2003:standard_sp1:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2003:web_edition_sp1:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_xp:*:*:home:*:*:*:*:*
cpe:2.3:o:microsoft:windows_xp:*:*:media_center:*:*:*:*:*
cpe:2.3:o:microsoft:windows_xp:*:*:pro:*:*:*:*:*
cpe:2.3:o:microsoft:windows_xp:*:*:x64:*:*:*:*:*
cpe:2.3:o:microsoft:windows_xp:*:sp1:home:*:*:*:*:*
cpe:2.3:o:microsoft:windows_xp:*:sp1:media_center:*:*:*:*:*
cpe:2.3:o:microsoft:windows_xp:*:sp1:pro:*:*:*:*:*
cpe:2.3:o:microsoft:windows_xp:*:sp2:media_center:*:*:*:*:*
cpe:2.3:o:microsoft:windows_xp:*:sp2:pro:*:*:*:*:*
cpe:2.3:o:microsoft:windows_xp:-:*:*:*:*:*:*:*

EPSS

Процентиль: 99%
0.75519
Высокий

9.3 Critical

CVSS2

Дефекты

CWE-119

Связанные уязвимости

github
почти 4 года назад

Buffer overflow in the plug-in for Microsoft Windows Media Player (WMP) 9 and 10, when used in browsers other than Internet Explorer and set as the default application to handle media files, allows remote attackers to execute arbitrary code via HTML with an EMBED element containing a long src attribute.

EPSS

Процентиль: 99%
0.75519
Высокий

9.3 Critical

CVSS2

Дефекты

CWE-119