[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248149

 
 

909

 
 

194803

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2006-1303Date: (C)2006-06-13   (M)2023-12-22


Multiple unspecified vulnerabilities in Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allow remote attackers to execute arbitrary code by instantiating certain COM objects from Wmm2fxa.dll as ActiveX controls including (1) DXImageTransform.Microsoft.MMSpecialEffect1Input, (2) DXImageTransform.Microsoft.MMSpecialEffect1Input.1, (3) DXImageTransform.Microsoft.MMSpecialEffect2Inputs, (4) DXImageTransform.Microsoft.MMSpecialEffect2Inputs.1, (5) DXImageTransform.Microsoft.MMSpecialEffectInplace1Input, and (6) DXImageTransform.Microsoft.MMSpecialEffectInplace1Input.1, which causes memory corruption during garbage collection.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 9.3
Exploit Score: 8.6
Impact Score: 10.0
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: COMPLETE
Integrity: COMPLETE
Availability: COMPLETE
  
Reference:
SECTRACK-1016291
BID-18328
http://www.securityfocus.com/archive/1/437041/100/0/threaded
SECUNIA-20595
OSVDB-26442
ADV-2006-2319
MS06-021
VU#959049
http://www.zerodayinitiative.com/advisories/ZDI-06-018.html
ie-wmm2fxadll-execute-code(26774)
oval:org.mitre.oval:def:1135
oval:org.mitre.oval:def:1767
oval:org.mitre.oval:def:1830
oval:org.mitre.oval:def:1928
oval:org.mitre.oval:def:1973
oval:org.mitre.oval:def:2017

CWE    1
CWE-94
OVAL    6
oval:org.mitre.oval:def:1928
oval:org.mitre.oval:def:1135
oval:org.mitre.oval:def:1767
oval:org.mitre.oval:def:1830
...

© SecPod Technologies