CVE-2006-0020
published 2006-01-10CVE-2006-0020: An unspecified Microsoft WMF parsing application, as used in Internet Explorer 5.01 SP4 on Windows 2000 SP4, and 5.5 SP2 on Windows Millennium, and possibly…
PriorityP334critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
18.50%
96.9th percentile
An unspecified Microsoft WMF parsing application, as used in Internet Explorer 5.01 SP4 on Windows 2000 SP4, and 5.5 SP2 on Windows Millennium, and possibly other versions, allows attackers to cause a denial of service (crash) and possibly execute code via a crafted WMF file with a manipulated WMF header size, possibly involving an integer overflow, a different vulnerability than CVE-2005-4560, and aka "WMF Image Parsing Memory Corruption Vulnerability."
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_2003_server | — | — |
| microsoft | windows_2003_server | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://linuxbox.org/pipermail/funsec/2006-January/002828.htmlhttp://secunia.com/advisories/18729http://secunia.com/advisories/18912http://www.kb.cert.org/vuls/id/312956http://www.microsoft.com/technet/security/advisory/913333.mspxhttp://www.osvdb.org/22976http://www.securityfocus.com/bid/16516http://www.us-cert.gov/cas/techalerts/TA06-045A.htmlhttp://www.vupen.com/english/advisories/2006/0469https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-004https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1638http://linuxbox.org/pipermail/funsec/2006-January/002828.htmlhttp://secunia.com/advisories/18729http://secunia.com/advisories/18912http://www.kb.cert.org/vuls/id/312956http://www.microsoft.com/technet/security/advisory/913333.mspxhttp://www.osvdb.org/22976http://www.securityfocus.com/bid/16516http://www.us-cert.gov/cas/techalerts/TA06-045A.htmlhttp://www.vupen.com/english/advisories/2006/0469https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-004https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1638
2006-01-10
Published