VDB
CVE-2006-5157
CVE-2006-5157
PUBLISHED
CVSS 5.099999904632568 MEDIUM
Format string vulnerability in the ActiveX control (ATXCONSOLE.OCX) in TrendMicro OfficeScan Corporate Edition (OSCE) before 7.3 Patch 1 allows remote attackers to execute arbitrary code via format string identifiers in the "Management Console's Remote Client Install name search".
EPSS 19.03% · 95.5th percentile
Risk Scores
CVSS 2.0
5.099999904632568
EPSS Score
19.03%
95.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | * |
| trend_micro | officescan | * |
Timeline
- Oct 3, 2006 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jun 30, 2023 EPSS Score
- Aug 7, 2023 EPSS Score
References
- http://www.layereddefense.com/TREND01OCT.html url
- ADV-2006-3870 vdb
- officescan-atxconsole-format-string(29308) vdb
- 1016963 vdb
- VU#788860 third-party-advisory
- 20284 vdb
- 20061001 Layered Defense Advisory: TrendMicro OfficesScan Corporate Edition Format String Vulnerability mailing-list
- 1682 third-party-advisory
- 22224 third-party-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2006-5157 advisory