{"api_version":"1","generated_at":"2026-07-24T20:42:17+00:00","cve":"CVE-2006-5577","urls":{"html":"https://cve.report/CVE-2006-5577","api":"https://cve.report/api/cve/CVE-2006-5577.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-5577","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-5577"},"summary":{"title":"CVE-2006-5577","description":"Microsoft Internet Explorer 6 and earlier allows remote attackers to obtain sensitive information via unspecified uses of the OBJECT HTML tag, which discloses the absolute path of the corresponding TIF folder, aka \"TIF Folder Information Disclosure Vulnerability,\" and a different issue than CVE-2006-5578.","state":"PUBLISHED","assigner":"microsoft","published_at":"2006-12-12 20:28:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:N/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.vupen.com/english/advisories/2006/4966","name":"http://www.vupen.com/english/advisories/2006/4966","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securitytracker.com/id?1017374","name":"http://securitytracker.com/id?1017374","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityTracker.com Archives - Microsoft Internet Explorer May Disclose Contents of the Temporary Internet Files Folder to Remote Users","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/21507","name":"http://www.securityfocus.com/bid/21507","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Microsoft Internet Explorer Object Tag TIF Folder Information Disclosure Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.us-cert.gov/cas/techalerts/TA06-346A.html","name":"http://www.us-cert.gov/cas/techalerts/TA06-346A.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["US Government Resource"],"title":"US-CERT Technical Cyber Security Alert TA06-346A -- Microsoft Updates for Multiple Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/23288","name":"http://secunia.com/advisories/23288","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Internet Explorer Multiple Vulnerabilities - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/30816","name":"http://www.osvdb.org/30816","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.securityfocus.com/archive/1/454969/100/200/threaded","name":"http://www.securityfocus.com/archive/1/454969/100/200/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A313","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A313","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-072","name":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-072","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Microsoft Security Bulletin MS06-072 - Critical | Microsoft Docs","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-5577","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-5577","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"5577","vulnerable":"1","versionEndIncluding":"6","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"ie","cpe6":"*","cpe7":"windows_server_2003_sp1","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T19:55:53.621Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"ADV-2006-4966","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2006/4966"},{"name":"23288","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/23288"},{"name":"TA06-346A","tags":["third-party-advisory","x_refsource_CERT","x_transferred"],"url":"http://www.us-cert.gov/cas/techalerts/TA06-346A.html"},{"name":"1017374","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1017374"},{"name":"oval:org.mitre.oval:def:313","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A313"},{"name":"21507","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/21507"},{"name":"SSRT061288","tags":["vendor-advisory","x_refsource_HP","x_transferred"],"url":"http://www.securityfocus.com/archive/1/454969/100/200/threaded"},{"name":"HPSBST02180","tags":["vendor-advisory","x_refsource_HP","x_transferred"],"url":"http://www.securityfocus.com/archive/1/454969/100/200/threaded"},{"name":"MS06-072","tags":["vendor-advisory","x_refsource_MS","x_transferred"],"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-072"},{"name":"30816","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/30816"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2006-12-12T00:00:00.000Z","descriptions":[{"lang":"en","value":"Microsoft Internet Explorer 6 and earlier allows remote attackers to obtain sensitive information via unspecified uses of the OBJECT HTML tag, which discloses the absolute path of the corresponding TIF folder, aka \"TIF Folder Information Disclosure Vulnerability,\" and a different issue than CVE-2006-5578."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-17T20:57:01.000Z","orgId":"f38d906d-7342-40ea-92c1-6c4a2c6478c8","shortName":"microsoft"},"references":[{"name":"ADV-2006-4966","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2006/4966"},{"name":"23288","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/23288"},{"name":"TA06-346A","tags":["third-party-advisory","x_refsource_CERT"],"url":"http://www.us-cert.gov/cas/techalerts/TA06-346A.html"},{"name":"1017374","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1017374"},{"name":"oval:org.mitre.oval:def:313","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A313"},{"name":"21507","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/21507"},{"name":"SSRT061288","tags":["vendor-advisory","x_refsource_HP"],"url":"http://www.securityfocus.com/archive/1/454969/100/200/threaded"},{"name":"HPSBST02180","tags":["vendor-advisory","x_refsource_HP"],"url":"http://www.securityfocus.com/archive/1/454969/100/200/threaded"},{"name":"MS06-072","tags":["vendor-advisory","x_refsource_MS"],"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-072"},{"name":"30816","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/30816"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"secure@microsoft.com","ID":"CVE-2006-5577","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Microsoft Internet Explorer 6 and earlier allows remote attackers to obtain sensitive information via unspecified uses of the OBJECT HTML tag, which discloses the absolute path of the corresponding TIF folder, aka \"TIF Folder Information Disclosure Vulnerability,\" and a different issue than CVE-2006-5578."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"ADV-2006-4966","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2006/4966"},{"name":"23288","refsource":"SECUNIA","url":"http://secunia.com/advisories/23288"},{"name":"TA06-346A","refsource":"CERT","url":"http://www.us-cert.gov/cas/techalerts/TA06-346A.html"},{"name":"1017374","refsource":"SECTRACK","url":"http://securitytracker.com/id?1017374"},{"name":"oval:org.mitre.oval:def:313","refsource":"OVAL","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A313"},{"name":"21507","refsource":"BID","url":"http://www.securityfocus.com/bid/21507"},{"name":"SSRT061288","refsource":"HP","url":"http://www.securityfocus.com/archive/1/454969/100/200/threaded"},{"name":"HPSBST02180","refsource":"HP","url":"http://www.securityfocus.com/archive/1/454969/100/200/threaded"},{"name":"MS06-072","refsource":"MS","url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-072"},{"name":"30816","refsource":"OSVDB","url":"http://www.osvdb.org/30816"}]}}}},"cveMetadata":{"assignerOrgId":"f38d906d-7342-40ea-92c1-6c4a2c6478c8","assignerShortName":"microsoft","cveId":"CVE-2006-5577","datePublished":"2006-12-12T20:00:00.000Z","dateReserved":"2006-10-27T00:00:00.000Z","dateUpdated":"2024-08-07T19:55:53.621Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2006-12-12 20:28:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:N/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:ie:*:windows_server_2003_sp1:*:*:*:*:*:*","versionEndIncluding":"6","matchCriteriaId":"66815960-CEFF-477A-A147-963A112206CF"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"5577","Ordinal":"1","Title":"CVE-2006-5577","CVE":"CVE-2006-5577","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"5577","Ordinal":"1","NoteData":"Microsoft Internet Explorer 6 and earlier allows remote attackers to obtain sensitive information via unspecified uses of the OBJECT HTML tag, which discloses the absolute path of the corresponding TIF folder, aka \"TIF Folder Information Disclosure Vulnerability,\" and a different issue than CVE-2006-5578.","Type":"Description","Title":"CVE-2006-5577"},{"CveYear":"2006","CveId":"5577","Ordinal":"2","NoteData":"2006-12-12","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"5577","Ordinal":"3","NoteData":"2018-10-17","Type":"Other","Title":"Modified"}]}}}