CVE-2006-0005
Summary
| CVE | CVE-2006-0005 |
|---|---|
| State | PUBLISHED |
| Assigner | microsoft |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-02-14 19:06:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | Buffer overflow in the plug-in for Microsoft Windows Media Player (WMP) 9 and 10, when used in browsers other than Internet Explorer and set as the default application to handle media files, allows remote attackers to execute arbitrary code via HTML with an EMBED element containing a long src attribute. |
Risk And Classification
Primary CVSS: v2.0 9.3 from [email protected]
AV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS: 0.755190000 probability, percentile 0.988970000 (date 2026-04-16)
Problem Types: CWE-119 | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:M/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Microsoft | Windows-nt | datacenter_server | All | All | All |
| Operating System | Microsoft | Windows-nt | datacenter_server | sp1 | All | All |
| Operating System | Microsoft | Windows-nt | datacenter_server | sp2 | All | All |
| Operating System | Microsoft | Windows-nt | datacenter_server | sp3 | All | All |
| Operating System | Microsoft | Windows-nt | datacenter_server | sp4 | All | All |
| Operating System | Microsoft | Windows-nt | xp | sp2 | home | All |
| Operating System | Microsoft | Windows-nt | xp_tablet_pc | All | All | All |
| Operating System | Microsoft | Windows-nt | xp_tablet_pc | sp1 | All | All |
| Operating System | Microsoft | Windows-nt | xp_tablet_pc | sp2 | All | All |
| Operating System | Microsoft | Windows 2000 | All | sp1 | pro | All |
| Operating System | Microsoft | Windows 2000 | All | sp2 | pro | All |
| Operating System | Microsoft | Windows 2000 | All | sp3 | pro | All |
| Operating System | Microsoft | Windows 2000 | All | sp4 | All | All |
| Operating System | Microsoft | Windows 2000 | All | sp4 | pro | All |
| Operating System | Microsoft | Windows 2000 | - | All | All | All |
| Operating System | Microsoft | Windows 2000 Advanced Server | All | All | All | All |
| Operating System | Microsoft | Windows 2000 Advanced Server | sp1 | All | All | All |
| Operating System | Microsoft | Windows 2000 Advanced Server | sp2 | All | All | All |
| Operating System | Microsoft | Windows 2000 Advanced Server | sp3 | All | All | All |
| Operating System | Microsoft | Windows 2000 Advanced Server | sp4 | All | All | All |
| Operating System | Microsoft | Windows 2003 Server | datacenter_edition | All | All | All |
| Operating System | Microsoft | Windows 2003 Server | datacenter_edition_64-bit | All | All | All |
| Operating System | Microsoft | Windows 2003 Server | enterprise_edition | All | All | All |
| Operating System | Microsoft | Windows 2003 Server | enterprise_edition_64-bit | All | All | All |
| Operating System | Microsoft | Windows 2003 Server | standard | All | All | All |
| Operating System | Microsoft | Windows 2003 Server | standard_64-bit | All | All | All |
| Operating System | Microsoft | Windows 2003 Server | web_edition | All | All | All |
| Operating System | Microsoft | Windows Server 2000 | none | All | All | All |
| Operating System | Microsoft | Windows Server 2000 | sp1 | All | All | All |
| Operating System | Microsoft | Windows Server 2000 | sp2 | All | All | All |
| Operating System | Microsoft | Windows Server 2000 | sp3 | All | All | All |
| Operating System | Microsoft | Windows Server 2003 | datacenter_sp1 | All | All | All |
| Operating System | Microsoft | Windows Server 2003 | enterprise_sp1 | All | All | All |
| Operating System | Microsoft | Windows Server 2003 | standard_sp1 | All | All | All |
| Operating System | Microsoft | Windows Server 2003 | web_edition_sp1 | All | All | All |
| Operating System | Microsoft | Windows Xp | All | All | home | All |
| Operating System | Microsoft | Windows Xp | All | All | media_center | All |
| Operating System | Microsoft | Windows Xp | All | All | pro | All |
| Operating System | Microsoft | Windows Xp | All | All | x64 | All |
| Operating System | Microsoft | Windows Xp | All | sp1 | home | All |
| Operating System | Microsoft | Windows Xp | All | sp1 | media_center | All |
| Operating System | Microsoft | Windows Xp | All | sp1 | pro | All |
| Operating System | Microsoft | Windows Xp | All | sp2 | media_center | All |
| Operating System | Microsoft | Windows Xp | All | sp2 | pro | All |
| Operating System | Microsoft | Windows Xp | - | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| US-CERT Technical Cyber Security Alert TA06-045A -- Microsoft Windows, Windows Media Player, and Internet Explorer Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.us-cert.gov | US Government Resource |
| Microsoft Security Bulletin MS06-006 - Critical | Microsoft Docs | af854a3a-2127-422b-91ae-364da2661108 | docs.microsoft.com | |
| SecurityTracker.com Archives - Windows Media Player Plug-in for 3rd Party Browsers Buffer Overflow in Processing EMBED Elements Lets Remote Users Execute Arbitrary Code | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| Windows Media Player Plug-in EMBED Element Buffer Overflow - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| US-CERT Vulnerability Note VU#692060 | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | US Government Resource |
| Microsoft Windows Media Player Plugin Buffer Overflow Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Accenture | Let there be change | af854a3a-2127-422b-91ae-364da2661108 | www.idefense.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.