VDB

CVE-2006-0005

CVE-2006-0005 PUBLISHED CVSS 9.300000190734863 CRITICAL

Buffer overflow in the plug-in for Microsoft Windows Media Player (WMP) 9 and 10, when used in browsers other than Internet Explorer and set as the default application to handle media files, allows remote attackers to execute arbitrary code via HTML with an EMBED element containing a long src attribute.

EPSS 75.52% · 98.9th percentile

Risk Scores

CVSS 2.0
9.300000190734863
EPSS Score
75.52%
98.9th percentile

Affected Products

VendorProductVersions
microsoftwindows_xp
microsoftwindows_2000_advanced_serversp1, sp4, *
microsoftwindows_2000
microsoftwindows-ntdatacenter_server, xp_tablet_pc, xp_tablet_pc
microsoftwindows_2003_serverenterprise_edition_64-bit, *, standard
n/an/an/a, *
microsoftwindows_server_2003standard_sp1, enterprise_sp1, standard_sp1
microsoftwindows_server_2000none, *, *

Timeline

  • Feb 14, 2006 CVE Published
  • Sep 26, 2008 VulnCheck KEV Exploitation
  • May 1, 2010 VulnCheck KEV Exploitation
  • Oct 18, 2012 VulnCheck KEV Exploitation
  • Feb 4, 2022 EPSS Score
  • Mar 29, 2022 EPSS Score
  • Jul 12, 2022 EPSS Score
  • Sep 4, 2022 EPSS Score
  • Dec 18, 2022 EPSS Score
  • Feb 9, 2023 EPSS Score
  • Apr 3, 2023 EPSS Score
  • May 25, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›