CVE-2006-4868
Summary
| CVE | CVE-2006-4868 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-09-19 19:07:00 UTC |
| Updated | 2021-07-23 12:55:00 UTC |
| Description | Stack-based buffer overflow in the Vector Graphics Rendering engine (vgx.dll), as used in Microsoft Outlook and Internet Explorer 6.0 on Windows XP SP2, and possibly other versions, allows remote attackers to execute arbitrary code via a Vector Markup Language (VML) file with a long fill parameter within a rect tag. |
Risk And Classification
Problem Types: CWE-119
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Microsoft | Ie | 5.0.1 | sp4 | All | All |
| Application | Microsoft | Ie | 6.0 | All | All | All |
| Application | Microsoft | Ie | 5.0.1 | sp4 | All | All |
| Application | Microsoft | Ie | 6.0 | All | All | All |
| Application | Microsoft | Internet Explorer | 5.0.1 | sp4 | All | All |
| Application | Microsoft | Internet Explorer | 6.0 | All | All | All |
| Application | Microsoft | Outlook | 2003 | All | All | All |
| Application | Microsoft | Outlook | 2003 | All | All | All |
| Operating System | Microsoft | Windows 2000 | All | sp4 | All | All |
| Operating System | Microsoft | Windows 2000 | All | sp4 | All | All |
| Operating System | Microsoft | Windows 2003 Server | All | All | All | All |
| Operating System | Microsoft | Windows 2003 Server | All | All | itanium | All |
| Operating System | Microsoft | Windows 2003 Server | All | All | x64 | All |
| Operating System | Microsoft | Windows 2003 Server | All | gold | All | All |
| Operating System | Microsoft | Windows 2003 Server | All | sp1 | All | All |
| Operating System | Microsoft | Windows 2003 Server | All | All | All | All |
| Operating System | Microsoft | Windows 2003 Server | All | All | itanium | All |
| Operating System | Microsoft | Windows 2003 Server | All | All | x64 | All |
| Operating System | Microsoft | Windows 2003 Server | All | gold | All | All |
| Operating System | Microsoft | Windows 2003 Server | All | sp1 | All | All |
| Operating System | Microsoft | Windows Xp | All | All | All | All |
| Operating System | Microsoft | Windows Xp | All | sp1 | All | All |
| Operating System | Microsoft | Windows Xp | All | sp2 | All | All |
| Operating System | Microsoft | Windows Xp | All | All | All | All |
| Operating System | Microsoft | Windows Xp | All | sp1 | All | All |
| Operating System | Microsoft | Windows Xp | All | sp2 | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Repository / Oval Repository | OVAL | oval.cisecurity.org | |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| SecurityFocus | HP | www.securityfocus.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | Vendor Advisory |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| SunbeltBLOG: Seen in the wild: Zero Day exploit being used to infect PCs | MISC | sunbeltblog.blogspot.com | |
| Microsoft Internet Explorer Vector Markup Language Buffer Overflow Vulnerability | BID | www.securityfocus.com | Exploit, Patch |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| MS06-055: Vulnerability in Vector Markup Language could allow remote code execution | MSKB | support.microsoft.com | |
| Microsoft Security Bulletin MS06-055 - Critical | Microsoft Docs | MS | docs.microsoft.com | |
| SecurityTracker.com Archives - Microsoft Internet Explorer VML Buffer Overflow Lets Remote Users Execute Arbitrary Code | SECTRACK | securitytracker.com | |
| 28946 | OSVDB | www.osvdb.org | |
| US-CERT Technical Cyber Security Alert TA06-262A -- Microsoft Internet Explorer VML Buffer Overflow | CERT | www.us-cert.gov | Patch, US Government Resource |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| SecuriTeam Blogs » Internet Explorer VML Zero-Day Mitigation | MISC | blogs.securiteam.com | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| Microsoft Vector Graphics Rendering Library Buffer Overflow - Advisories - Secunia | SECUNIA | secunia.com | Patch, Vendor Advisory |
| US-CERT Vulnerability Note VU#416092 | CERT-VN | www.kb.cert.org | US Government Resource |
| Your request has been blocked. This could be due to several reasons. | CONFIRM | www.microsoft.com | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.