CVE-2006-3649
Summary
| CVE | CVE-2006-3649 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-08-09 00:04:00 UTC |
| Updated | 2018-10-12 21:40:00 UTC |
| Description | Buffer overflow in Microsoft Visual Basic for Applications (VBA) SDK 6.0 through 6.4, as used by Microsoft Office 2000 SP3, Office XP SP3, Project 2000 SR1, Project 2002 SP1, Access 2000 Runtime SP3, Visio 2002 SP2, and Works Suite 2004 through 2006, allows user-assisted attackers to execute arbitrary code via unspecified document properties that are not verified when VBA is invoked to open documents. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Microsoft | Visual Basic | 6.2 | All | All | All |
| Application | Microsoft | Visual Basic | 6.2 | All | sdk | All |
| Application | Microsoft | Visual Basic | 6.3 | All | sdk | All |
| Application | Microsoft | Visual Basic | 6.4 | All | sdk | All |
| Application | Microsoft | Visual Basic | 6.2 | All | All | All |
| Application | Microsoft | Visual Basic | 6.2 | All | sdk | All |
| Application | Microsoft | Visual Basic | 6.3 | All | sdk | All |
| Application | Microsoft | Visual Basic | 6.4 | All | sdk | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| SecurityTracker.com Archives - Microsoft Visual Basic for Applications Buffer Overflow Lets Remote Users Execute Arbitrary Code | SECTRACK | securitytracker.com | |
| Microsoft Security Bulletin MS06-047 - Critical | Microsoft Docs | MS | docs.microsoft.com | |
| Microsoft Visual Basic for Applications Document Check Buffer Overflow Vulnerability | BID | www.securityfocus.com | |
| US-CERT Technical Cyber Security Alert TA06-220A -- Microsoft Products Contain Multiple Vulnerabilities | CERT | www.us-cert.gov | Patch, US Government Resource |
| Repository / Oval Repository | OVAL | oval.cisecurity.org | |
| US-CERT Vulnerability Note VU#159484 | CERT-VN | www.kb.cert.org | Patch, US Government Resource |
| Microsoft Visual Basic for Applications Buffer Overflow - Advisories - Secunia | SECUNIA | secunia.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.