CVE-2006-1308
published 2006-07-13CVE-2006-1308: Unspecified vulnerability in Microsoft Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via a .xls file with a crafted…
PriorityP338critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
9.28%
94.8th percentile
Unspecified vulnerability in Microsoft Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via a .xls file with a crafted FNGROUPCOUNT value.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | excel | — | — |
| microsoft | excel | — | — |
| microsoft | excel | — | — |
| microsoft | excel | — | — |
| microsoft | excel | — | — |
| microsoft | excel_viewer | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat4.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cj6v-crpc-f3x5: Unspecified vulnerability in Microsoft Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via a
ghsa_unreviewed·2022-05-01
CVE-2006-1308 [HIGH] CWE-94 GHSA-cj6v-crpc-f3x5: Unspecified vulnerability in Microsoft Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via a
Unspecified vulnerability in Microsoft Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via a .xls file with a crafted FNGROUPCOUNT value.
Red Hat
CVE-2006-5969: CRLF injection vulnerability in the evalFolderLine function in fvwm 2
vendor_redhat·CVSS 4.6
CVE-2006-5969 [MEDIUM] CVE-2006-5969: CRLF injection vulnerability in the evalFolderLine function in fvwm 2
CRLF injection vulnerability in the evalFolderLine function in fvwm 2.5.18 and earlier allows local users to execute arbitrary commands via carriage returns in a directory name, which is not properly handled by fvwm-menu-directory, a variant of CVE-2003-1308.
Statement: Not vulnerable. Red Hat Enterprise Linux 2.1 shipped with fvwm, however this issue does not affect the included version of fvwm.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://lists.grok.org.uk/pipermail/full-disclosure/2006-July/047837.htmlhttp://securitytracker.com/id?1016472http://www.securityfocus.com/bid/18890http://www.vupen.com/english/advisories/2006/2755https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-037https://exchange.xforce.ibmcloud.com/vulnerabilities/27464https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A243http://lists.grok.org.uk/pipermail/full-disclosure/2006-July/047837.htmlhttp://securitytracker.com/id?1016472http://www.securityfocus.com/bid/18890http://www.vupen.com/english/advisories/2006/2755https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-037https://exchange.xforce.ibmcloud.com/vulnerabilities/27464https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A243
2006-07-13
Published