{"api_version":"1","generated_at":"2026-07-23T12:07:31+00:00","cve":"CVE-2006-3888","urls":{"html":"https://cve.report/CVE-2006-3888","api":"https://cve.report/api/cve/CVE-2006-3888.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-3888","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-3888"},"summary":{"title":"CVE-2006-3888","description":"Buffer overflow in AOL You've Got Pictures (YGP) Pic Downloader YGPPDownload ActiveX control (AOL.PicDownloadCtrl.1, YGPPicDownload.dll), as used in America Online 9.0 Security Edition, allows remote attackers to execute arbitrary code via a long argument to the SetAlbumName method.","state":"PUBLISHED","assigner":"certcc","published_at":"2006-10-10 23:07:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.securityfocus.com/bid/20472","name":"http://www.securityfocus.com/bid/20472","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"AOL You've Got Pictures SetAlbumName ActiveX Control Buffer Overflow Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.kb.cert.org/vuls/id/661524","name":"http://www.kb.cert.org/vuls/id/661524","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["US Government Resource"],"title":"US-CERT Vulnerability Note VU#661524","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=420","name":"http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=420","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/20425","name":"http://www.securityfocus.com/bid/20425","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"AOL You've Got Pictures ActiveX Controls Buffer Overflow Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/29410","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/29410","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2006/3967","name":"http://www.vupen.com/english/advisories/2006/3967","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/22304","name":"http://secunia.com/advisories/22304","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"AOL YGP ActiveX Controls Buffer Overflow Vulnerabilities - Secunia Advisories - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.kb.cert.org/vuls/id/MIMG-6MUUJ8","name":"http://www.kb.cert.org/vuls/id/MIMG-6MUUJ8","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"America Online, Inc. Information for VU#661524","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/29494","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/29494","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securitytracker.com/id?1017024","name":"http://securitytracker.com/id?1017024","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityTracker.com Archives - AOL Buffer Overflows in You've Got Pictures ActiveX Controls Lets Remote Users Execute Arbitrary Code","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-3888","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-3888","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"3888","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"aol","cpe5":"ygp_pic_downloader_activex_control","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T18:48:39.209Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"ADV-2006-3967","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2006/3967"},{"name":"20472","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/20472"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.kb.cert.org/vuls/id/MIMG-6MUUJ8"},{"name":"1017024","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1017024"},{"name":"VU#661524","tags":["third-party-advisory","x_refsource_CERT-VN","x_transferred"],"url":"http://www.kb.cert.org/vuls/id/661524"},{"name":"20061011 AOL YGPPDownload SetAlbumName ActiveX Control Buffer Overflow Vulnerability","tags":["third-party-advisory","x_refsource_IDEFENSE","x_transferred"],"url":"http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=420"},{"name":"aol-ygp-pic-downloader-bo(29410)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/29410"},{"name":"20425","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/20425"},{"name":"aol-ygp-setalbumname-bo(29494)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/29494"},{"name":"22304","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/22304"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2006-10-09T00:00:00.000Z","descriptions":[{"lang":"en","value":"Buffer overflow in AOL You've Got Pictures (YGP) Pic Downloader YGPPDownload ActiveX control (AOL.PicDownloadCtrl.1, YGPPicDownload.dll), as used in America Online 9.0 Security Edition, allows remote attackers to execute arbitrary code via a long argument to the SetAlbumName method."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-19T15:57:01.000Z","orgId":"37e5125f-f79b-445b-8fad-9564f167944b","shortName":"certcc"},"references":[{"name":"ADV-2006-3967","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2006/3967"},{"name":"20472","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/20472"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.kb.cert.org/vuls/id/MIMG-6MUUJ8"},{"name":"1017024","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1017024"},{"name":"VU#661524","tags":["third-party-advisory","x_refsource_CERT-VN"],"url":"http://www.kb.cert.org/vuls/id/661524"},{"name":"20061011 AOL YGPPDownload SetAlbumName ActiveX Control Buffer Overflow Vulnerability","tags":["third-party-advisory","x_refsource_IDEFENSE"],"url":"http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=420"},{"name":"aol-ygp-pic-downloader-bo(29410)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/29410"},{"name":"20425","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/20425"},{"name":"aol-ygp-setalbumname-bo(29494)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/29494"},{"name":"22304","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/22304"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cert@cert.org","ID":"CVE-2006-3888","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Buffer overflow in AOL You've Got Pictures (YGP) Pic Downloader YGPPDownload ActiveX control (AOL.PicDownloadCtrl.1, YGPPicDownload.dll), as used in America Online 9.0 Security Edition, allows remote attackers to execute arbitrary code via a long argument to the SetAlbumName method."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"ADV-2006-3967","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2006/3967"},{"name":"20472","refsource":"BID","url":"http://www.securityfocus.com/bid/20472"},{"name":"http://www.kb.cert.org/vuls/id/MIMG-6MUUJ8","refsource":"CONFIRM","url":"http://www.kb.cert.org/vuls/id/MIMG-6MUUJ8"},{"name":"1017024","refsource":"SECTRACK","url":"http://securitytracker.com/id?1017024"},{"name":"VU#661524","refsource":"CERT-VN","url":"http://www.kb.cert.org/vuls/id/661524"},{"name":"20061011 AOL YGPPDownload SetAlbumName ActiveX Control Buffer Overflow Vulnerability","refsource":"IDEFENSE","url":"http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=420"},{"name":"aol-ygp-pic-downloader-bo(29410)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/29410"},{"name":"20425","refsource":"BID","url":"http://www.securityfocus.com/bid/20425"},{"name":"aol-ygp-setalbumname-bo(29494)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/29494"},{"name":"22304","refsource":"SECUNIA","url":"http://secunia.com/advisories/22304"}]}}}},"cveMetadata":{"assignerOrgId":"37e5125f-f79b-445b-8fad-9564f167944b","assignerShortName":"certcc","cveId":"CVE-2006-3888","datePublished":"2006-10-10T23:00:00.000Z","dateReserved":"2006-07-26T00:00:00.000Z","dateUpdated":"2024-08-07T18:48:39.209Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2006-10-10 23:07:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:aol:ygp_pic_downloader_activex_control:*:*:*:*:*:*:*:*","matchCriteriaId":"5F6B7286-87C3-4AB6-AAF8-682805120784"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"3888","Ordinal":"1","Title":"CVE-2006-3888","CVE":"CVE-2006-3888","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"3888","Ordinal":"1","NoteData":"Buffer overflow in AOL You've Got Pictures (YGP) Pic Downloader YGPPDownload ActiveX control (AOL.PicDownloadCtrl.1, YGPPicDownload.dll), as used in America Online 9.0 Security Edition, allows remote attackers to execute arbitrary code via a long argument to the SetAlbumName method.","Type":"Description","Title":"CVE-2006-3888"},{"CveYear":"2006","CveId":"3888","Ordinal":"2","NoteData":"2006-10-10","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"3888","Ordinal":"3","NoteData":"2017-07-19","Type":"Other","Title":"Modified"}]}}}