{"api_version":"1","generated_at":"2026-07-24T20:47:17+00:00","cve":"CVE-2006-5559","urls":{"html":"https://cve.report/CVE-2006-5559","api":"https://cve.report/api/cve/CVE-2006-5559.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-5559","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-5559"},"summary":{"title":"CVE-2006-5559","description":"The Execute method in the ADODB.Connection 2.7 and 2.8 ActiveX control objects (ADODB.Connection.2.7 and ADODB.Connection.2.8) in the Microsoft Data Access Components (MDAC) 2.5 SP3, 2.7 SP1, 2.8, and 2.8 SP1 does not properly track freed memory when the second argument is a BSTR, which allows remote attackers to cause a denial of service (Internet Explorer crash) and possibly execute arbitrary code via certain strings in the second and third arguments.","state":"PUBLISHED","assigner":"mitre","published_at":"2006-10-27 16:07:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-20","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"9.3","severity":"","vector":"AV:N/AC:M/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://www.securityfocus.com/bid/20704","name":"http://www.securityfocus.com/bid/20704","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Patch"],"title":"Microsoft Internet Explorer ADODB.Connection Execute Memory Corruption Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://research.eeye.com/html/alerts/zeroday/20061027.html","name":"http://research.eeye.com/html/alerts/zeroday/20061027.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"Resources | BeyondTrust","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.kb.cert.org/vuls/id/589272","name":"http://www.kb.cert.org/vuls/id/589272","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","US Government Resource"],"title":"US-CERT Vulnerability Note VU#589272","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2007/0578","name":"http://www.vupen.com/english/advisories/2007/0578","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/22452","name":"http://secunia.com/advisories/22452","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Microsoft MDAC ADODB.Connection ActiveX Control Vulnerability - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/31882","name":"http://www.osvdb.org/31882","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://blogs.technet.com/msrc/archive/2006/10/27/adodb-connection-poc-published.aspx","name":"http://blogs.technet.com/msrc/archive/2006/10/27/adodb-connection-poc-published.aspx","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Welcome to the Microsoft Security Response Center Blog! : ADODB.Connection POC Published.","mime":"text/html","httpstatus":"503","archivestatus":"200"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A214","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A214","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/29837","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/29837","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.us-cert.gov/cas/techalerts/TA07-044A.html","name":"http://www.us-cert.gov/cas/techalerts/TA07-044A.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["US Government Resource"],"title":"US-CERT Technical Cyber Security Alert TA07-044A -- Microsoft Updates for Multiple Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-009","name":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-009","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Microsoft Security Bulletin MS07-009 - Critical | Microsoft Docs","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securitytracker.com/id?1017127","name":"http://securitytracker.com/id?1017127","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Patch","Vendor Advisory"],"title":"SecurityTracker.com Archives - Microsoft Data Access Components 'ADODB.Connection' Execute Function Lets Remote Users Execute Arbitrary Code","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-5559","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-5559","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"5559","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"data_access_components","cpe6":"2.5","cpe7":"sp3","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"5559","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"data_access_components","cpe6":"2.8","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"5559","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"data_access_components","cpe6":"2.8","cpe7":"sp1","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"5559","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_2000","cpe6":"*","cpe7":"sp4","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"5559","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_2003_server","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"5559","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_2003_server","cpe6":"itanium","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"5559","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_xp","cpe6":"*","cpe7":"sp2","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T19:55:53.686Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"1017127","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1017127"},{"name":"MS07-009","tags":["vendor-advisory","x_refsource_MS","x_transferred"],"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-009"},{"name":"20704","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/20704"},{"name":"oval:org.mitre.oval:def:214","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A214"},{"name":"22452","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/22452"},{"name":"TA07-044A","tags":["third-party-advisory","x_refsource_CERT","x_transferred"],"url":"http://www.us-cert.gov/cas/techalerts/TA07-044A.html"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://research.eeye.com/html/alerts/zeroday/20061027.html"},{"name":"VU#589272","tags":["third-party-advisory","x_refsource_CERT-VN","x_transferred"],"url":"http://www.kb.cert.org/vuls/id/589272"},{"name":"ie-adodbconnection-Code-Execution(29837)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/29837"},{"name":"31882","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/31882"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://blogs.technet.com/msrc/archive/2006/10/27/adodb-connection-poc-published.aspx"},{"name":"ADV-2007-0578","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2007/0578"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2006-10-25T00:00:00.000Z","descriptions":[{"lang":"en","value":"The Execute method in the ADODB.Connection 2.7 and 2.8 ActiveX control objects (ADODB.Connection.2.7 and ADODB.Connection.2.8) in the Microsoft Data Access Components (MDAC) 2.5 SP3, 2.7 SP1, 2.8, and 2.8 SP1 does not properly track freed memory when the second argument is a BSTR, which allows remote attackers to cause a denial of service (Internet Explorer crash) and possibly execute arbitrary code via certain strings in the second and third arguments."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-12T19:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"1017127","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1017127"},{"name":"MS07-009","tags":["vendor-advisory","x_refsource_MS"],"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-009"},{"name":"20704","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/20704"},{"name":"oval:org.mitre.oval:def:214","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A214"},{"name":"22452","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/22452"},{"name":"TA07-044A","tags":["third-party-advisory","x_refsource_CERT"],"url":"http://www.us-cert.gov/cas/techalerts/TA07-044A.html"},{"tags":["x_refsource_MISC"],"url":"http://research.eeye.com/html/alerts/zeroday/20061027.html"},{"name":"VU#589272","tags":["third-party-advisory","x_refsource_CERT-VN"],"url":"http://www.kb.cert.org/vuls/id/589272"},{"name":"ie-adodbconnection-Code-Execution(29837)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/29837"},{"name":"31882","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/31882"},{"tags":["x_refsource_MISC"],"url":"http://blogs.technet.com/msrc/archive/2006/10/27/adodb-connection-poc-published.aspx"},{"name":"ADV-2007-0578","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2007/0578"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2006-5559","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The Execute method in the ADODB.Connection 2.7 and 2.8 ActiveX control objects (ADODB.Connection.2.7 and ADODB.Connection.2.8) in the Microsoft Data Access Components (MDAC) 2.5 SP3, 2.7 SP1, 2.8, and 2.8 SP1 does not properly track freed memory when the second argument is a BSTR, which allows remote attackers to cause a denial of service (Internet Explorer crash) and possibly execute arbitrary code via certain strings in the second and third arguments."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"1017127","refsource":"SECTRACK","url":"http://securitytracker.com/id?1017127"},{"name":"MS07-009","refsource":"MS","url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-009"},{"name":"20704","refsource":"BID","url":"http://www.securityfocus.com/bid/20704"},{"name":"oval:org.mitre.oval:def:214","refsource":"OVAL","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A214"},{"name":"22452","refsource":"SECUNIA","url":"http://secunia.com/advisories/22452"},{"name":"TA07-044A","refsource":"CERT","url":"http://www.us-cert.gov/cas/techalerts/TA07-044A.html"},{"name":"http://research.eeye.com/html/alerts/zeroday/20061027.html","refsource":"MISC","url":"http://research.eeye.com/html/alerts/zeroday/20061027.html"},{"name":"VU#589272","refsource":"CERT-VN","url":"http://www.kb.cert.org/vuls/id/589272"},{"name":"ie-adodbconnection-Code-Execution(29837)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/29837"},{"name":"31882","refsource":"OSVDB","url":"http://www.osvdb.org/31882"},{"name":"http://blogs.technet.com/msrc/archive/2006/10/27/adodb-connection-poc-published.aspx","refsource":"MISC","url":"http://blogs.technet.com/msrc/archive/2006/10/27/adodb-connection-poc-published.aspx"},{"name":"ADV-2007-0578","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2007/0578"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2006-5559","datePublished":"2006-10-27T16:00:00.000Z","dateReserved":"2006-10-27T00:00:00.000Z","dateUpdated":"2024-08-07T19:55:53.686Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2006-10-27 16:07:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-20","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":8.6,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":true,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_2000:*:sp4:*:*:*:*:*:*","matchCriteriaId":"83E7C4A0-78CF-4B56-82BF-EC932BDD8ADF"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:data_access_components:2.5:sp3:*:*:*:*:*:*","matchCriteriaId":"B901D0A6-2F68-4CAC-B985-6A2BA0A1705B"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_xp:*:sp2:*:*:*:*:*:*","matchCriteriaId":"9B339C33-8896-4896-88FF-88E74FDBC543"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:data_access_components:2.8:sp1:*:*:*:*:*:*","matchCriteriaId":"036C836C-6387-4DAC-96B2-94C979D236E8"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_2003_server:*:*:*:*:*:*:*:*","matchCriteriaId":"60EC86B8-5C8C-4873-B364-FB1F8EFE1CFF"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_2003_server:itanium:*:*:*:*:*:*:*","matchCriteriaId":"0808041A-CE1A-433A-9C2B-019097CCFB0C"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:data_access_components:2.8:*:*:*:*:*:*:*","matchCriteriaId":"1F233914-2763-42E8-BCB9-E0D1186783E8"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_2000:*:sp4:*:*:*:*:*:*","matchCriteriaId":"83E7C4A0-78CF-4B56-82BF-EC932BDD8ADF"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:data_access_components:2.7:sp1:*:*:*:*:*:*","matchCriteriaId":"819DDAAF-D9A3-4540-B467-2A7233D36038"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_2000:*:sp4:*:*:*:*:*:*","matchCriteriaId":"83E7C4A0-78CF-4B56-82BF-EC932BDD8ADF"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:data_access_components:2.8:*:*:*:*:*:*:*","matchCriteriaId":"1F233914-2763-42E8-BCB9-E0D1186783E8"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_2000:*:sp4:*:*:*:*:*:*","matchCriteriaId":"83E7C4A0-78CF-4B56-82BF-EC932BDD8ADF"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:data_access_components:2.8:sp1:*:*:*:*:*:*","matchCriteriaId":"036C836C-6387-4DAC-96B2-94C979D236E8"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"5559","Ordinal":"1","Title":"CVE-2006-5559","CVE":"CVE-2006-5559","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"5559","Ordinal":"1","NoteData":"The Execute method in the ADODB.Connection 2.7 and 2.8 ActiveX control objects (ADODB.Connection.2.7 and ADODB.Connection.2.8) in the Microsoft Data Access Components (MDAC) 2.5 SP3, 2.7 SP1, 2.8, and 2.8 SP1 does not properly track freed memory when the second argument is a BSTR, which allows remote attackers to cause a denial of service (Internet Explorer crash) and possibly execute arbitrary code via certain strings in the second and third arguments.","Type":"Description","Title":"CVE-2006-5559"},{"CveYear":"2006","CveId":"5559","Ordinal":"2","NoteData":"2006-10-27","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"5559","Ordinal":"3","NoteData":"2018-10-12","Type":"Other","Title":"Modified"}]}}}