CVE-2006-4777
Summary
| CVE | CVE-2006-4777 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-09-14 00:07:00 UTC |
| Updated | 2018-10-17 21:39:00 UTC |
| Description | Heap-based buffer overflow in the DirectAnimation Path Control (DirectAnimation.PathControl) COM object (daxctle.ocx) for Internet Explorer 6.0 SP1, on Chinese and possibly other Windows distributions, allows remote attackers to execute arbitrary code via unknown manipulations in arguments to the KeyFrame method, possibly related to an integer overflow, as demonstrated by daxctle2, and a different vulnerability than CVE-2006-4446. |
Risk And Classification
Problem Types: CWE-119
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 28842 | OSVDB | www.osvdb.org | |
| US-CERT Vulnerability Note VU#377369 | CERT-VN | www.kb.cert.org | US Government Resource |
| Microsoft Internet Explorer Daxctle.OCX KeyFrame Method Heap Buffer Overflow Vulnerability | BID | www.securityfocus.com | |
| US-CERT Technical Cyber Security Alert TA06-318A -- Microsoft Security Updates for Windows, Internet Explorer, and Adobe Flash | CERT | www.us-cert.gov | US Government Resource |
| Your request has been blocked. This could be due to several reasons. | CONFIRM | www.microsoft.com | |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| SecurityReason - [0day] daxctle2.c - Internet Explorer COM Object Heap Overflow Download Exec Exploit | SREASON | securityreason.com | |
| Microsoft Security Bulletin MS06-067 - Critical | Microsoft Docs | MS | docs.microsoft.com | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| Internet Explorer Multiple Vulnerabilities - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | Vendor Advisory |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| XSec => daxctle2.c - Internet Explorer COM Object Heap Overflow Download Exec Exploit | MISC | www.xsec.org | |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| Repository / Oval Repository | OVAL | oval.cisecurity.org | |
| SecurityTracker.com Archives - Microsoft Internet Explorer Buffer Overflow in 'daxctle.ocx' ActiveX in KeyFrame Method Control Lets Remote Users Execute Arbitrary Code | SECTRACK | securitytracker.com | |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.