CVE-2006-3014
Summary
| CVE | CVE-2006-3014 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-06-22 00:06:00 UTC |
| Updated | 2018-10-12 21:40:00 UTC |
| Description | Microsoft Excel allows user-assisted attackers to execute arbitrary javascript and redirect users to arbitrary sites via an Excel spreadsheet with an embedded Shockwave Flash Player ActiveX Object, which is automatically executed when the user opens the spreadsheet. |
Risk And Classification
Problem Types: CWE-20
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| Repository / Oval Repository | OVAL | oval.cisecurity.org | |
| US-CERT Technical Cyber Security Alert TA06-318A -- Microsoft Security Updates for Windows, Internet Explorer, and Adobe Flash | CERT | www.us-cert.gov | US Government Resource |
| Neohapsis Archives - Full Disclosure List - #0414 - [Full-disclosure] Microsoft Excel File Embedded Shockwave Flash Object Exploit | FULLDISC | archives.neohapsis.com | Exploit |
| Webmail - OVH | VUPEN | www.vupen.com | Vendor Advisory |
| Adobe - Security Advisories : Multiple Vulnerabilities in Adobe Flash Player 8.0.24.0 and Earlier Versions | CONFIRM | www.adobe.com | |
| Webmail - OVH | VUPEN | www.vupen.com | Vendor Advisory |
| Adobe Flash Player Multiple Vulnerabilities - Advisories - Secunia | SECUNIA | secunia.com | Patch, Vendor Advisory |
| hackingspirits.com - hackingspirits Resources and Information. | MISC | hackingspirits.com | Exploit |
| Adobe Flash Player Multiple Remote Code Execution Vulnerabilities | BID | www.securityfocus.com | Patch |
| Microsoft Windows Flash Player Multiple Vulnerabilities - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| SecuriTeam - Microsoft Excel File Embedded Shockwave Flash Object Local Execution | MISC | www.securiteam.com | |
| Microsoft Security Bulletin MS06-069 - Critical | Microsoft Docs | MS | docs.microsoft.com | |
| Microsoft Office Embedded Shockwave Flash Object Security Bypass Weakness | BID | www.securityfocus.com | Exploit |
| SecurityTracker.com Archives - Microsoft Excel 'Shockwave Flash Object' Lets Remote Users Execute Code Automatically | SECTRACK | securitytracker.com | |
| Webmail - OVH | VUPEN | www.vupen.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.