VDB
CVE-2006-0005
CVE-2006-0005
PUBLISHED
CVSS 9.300000190734863 CRITICAL
Buffer overflow in the plug-in for Microsoft Windows Media Player (WMP) 9 and 10, when used in browsers other than Internet Explorer and set as the default application to handle media files, allows remote attackers to execute arbitrary code via HTML with an EMBED element containing a long src attribute.
EPSS 75.52% · 98.9th percentile
Risk Scores
CVSS 2.0
9.300000190734863
EPSS Score
75.52%
98.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| microsoft | windows_xp | |
| microsoft | windows_2000_advanced_server | sp1, sp4, * |
| microsoft | windows_2000 | |
| microsoft | windows-nt | datacenter_server, xp_tablet_pc, xp_tablet_pc |
| microsoft | windows_2003_server | enterprise_edition_64-bit, *, standard |
| n/a | n/a | n/a, * |
| microsoft | windows_server_2003 | standard_sp1, enterprise_sp1, standard_sp1 |
| microsoft | windows_server_2000 | none, *, * |
Timeline
- Feb 14, 2006 CVE Published
- Sep 26, 2008 VulnCheck KEV Exploitation
- May 1, 2010 VulnCheck KEV Exploitation
- Oct 18, 2012 VulnCheck KEV Exploitation
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 25, 2023 EPSS Score
References
- ADV-2006-0575 vdb
- 16644 vdb
- win-mediaplayer-plugin-embed-bo(24493) vdb
- 1015628 vdb
- VU#692060 third-party-advisory
- 20060214 Microsoft Windows Media Player Plugin Buffer Overflow Vulnerability third-party-advisory
- MS06-006 vendor-advisory
- oval:org.mitre.oval:def:1559 vdb
- TA06-045A third-party-advisory
- 18852 third-party-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2006-0005 advisory