CVE-2006-3869
published 2006-08-23CVE-2006-3869: Heap-based buffer overflow in URLMON.DLL in Microsoft Internet Explorer 6 SP1 on Windows 2000 and XP SP1, with versions the MS06-042 patch before 20060824…
PriorityP341high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
43.06%
98.6th percentile
Heap-based buffer overflow in URLMON.DLL in Microsoft Internet Explorer 6 SP1 on Windows 2000 and XP SP1, with versions the MS06-042 patch before 20060824, allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long URL on a website that uses HTTP 1.1 compression.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | ie | — | — |
| microsoft | windows_2003_server | — | — |
| microsoft | windows_2003_server | — | — |
| microsoft | windows_2003_server | — | — |
| microsoft | windows_2003_server | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-p2jw-xr8p-fh9v: Heap-based buffer overflow in URLMON
ghsa_unreviewed·2022-05-01·CVSS 7.5
CVE-2006-3873 [HIGH] GHSA-p2jw-xr8p-fh9v: Heap-based buffer overflow in URLMON
Heap-based buffer overflow in URLMON.DLL in Microsoft Internet Explorer 6 SP1 on Windows 2000 and XP SP1, with versions the MS06-042 patch before 20060912, allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long URL in a GZIP-encoded website that was the target of an HTTP redirect, due to an incomplete fix for CVE-2006-3869.
GHSA
GHSA-wvv3-wwf7-9f6m: Heap-based buffer overflow in URLMON
ghsa_unreviewed·2022-05-01
CVE-2006-3869 [HIGH] GHSA-wvv3-wwf7-9f6m: Heap-based buffer overflow in URLMON
Heap-based buffer overflow in URLMON.DLL in Microsoft Internet Explorer 6 SP1 on Windows 2000 and XP SP1, with versions the MS06-042 patch before 20060824, allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long URL on a website that uses HTTP 1.1 compression.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/21557http://securityreason.com/securityalert/1441http://securitytracker.com/id?1016731http://support.microsoft.com/kb/923762/http://www.kb.cert.org/vuls/id/821156http://www.microsoft.com/technet/security/advisory/923762.mspxhttp://www.nsfocus.com/english/homepage/research/0608.htmhttp://www.osvdb.org/28132http://www.securityfocus.com/archive/1/444046/100/0/threadedhttp://www.securityfocus.com/archive/1/444241/100/0/threadedhttp://www.securityfocus.com/archive/1/444319/100/0/threadedhttp://www.securityfocus.com/bid/19667http://www.vupen.com/english/advisories/2006/3356https://exchange.xforce.ibmcloud.com/vulnerabilities/28522https://exchange.xforce.ibmcloud.com/vulnerabilities/28893http://secunia.com/advisories/21557http://securityreason.com/securityalert/1441http://securitytracker.com/id?1016731http://support.microsoft.com/kb/923762/http://www.kb.cert.org/vuls/id/821156http://www.microsoft.com/technet/security/advisory/923762.mspxhttp://www.nsfocus.com/english/homepage/research/0608.htmhttp://www.osvdb.org/28132http://www.securityfocus.com/archive/1/444046/100/0/threadedhttp://www.securityfocus.com/archive/1/444241/100/0/threadedhttp://www.securityfocus.com/archive/1/444319/100/0/threadedhttp://www.securityfocus.com/bid/19667http://www.vupen.com/english/advisories/2006/3356https://exchange.xforce.ibmcloud.com/vulnerabilities/28522https://exchange.xforce.ibmcloud.com/vulnerabilities/28893
2006-08-23
Published