{"api_version":"1","generated_at":"2026-07-23T09:17:37+00:00","cve":"CVE-2006-5579","urls":{"html":"https://cve.report/CVE-2006-5579","api":"https://cve.report/api/cve/CVE-2006-5579.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-5579","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-5579"},"summary":{"title":"CVE-2006-5579","description":"Microsoft Internet Explorer 6 allows remote attackers to execute arbitrary code by using JavaScript to cause certain errors simultaneously, which results in the access of previously freed memory, aka \"Script Error Handling Memory Corruption Vulnerability.\"","state":"PUBLISHED","assigner":"microsoft","published_at":"2006-12-12 20:28:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-119","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"9.3","severity":"","vector":"AV:N/AC:M/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://www.vupen.com/english/advisories/2006/4966","name":"http://www.vupen.com/english/advisories/2006/4966","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A761","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A761","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.kb.cert.org/vuls/id/599832","name":"http://www.kb.cert.org/vuls/id/599832","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["US Government Resource"],"title":"US-CERT Vulnerability Note VU#599832","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/30813","name":"http://www.osvdb.org/30813","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.us-cert.gov/cas/techalerts/TA06-346A.html","name":"http://www.us-cert.gov/cas/techalerts/TA06-346A.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["US Government Resource"],"title":"US-CERT Technical Cyber Security Alert TA06-346A -- Microsoft Updates for Multiple Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/454205/100/0/threaded","name":"http://www.securityfocus.com/archive/1/454205/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securitytracker.com/id?1017373","name":"http://securitytracker.com/id?1017373","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityTracker.com Archives - Microsoft Internet Explorer DHTML and Script Error Handling Bugs Let Remote Users Execute Arbitrary Code","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/454969/100/200/threaded","name":"http://www.securityfocus.com/archive/1/454969/100/200/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-072","name":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-072","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Microsoft Security Bulletin MS06-072 - Critical | Microsoft Docs","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/20807","name":"http://secunia.com/advisories/20807","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Internet Explorer Script Error Handling Memory Corruption Vulnerability - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/21552","name":"http://www.securityfocus.com/bid/21552","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Microsoft Internet Explorer Script Error Handling Remote Code Execution Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://secunia.com/secunia_research/2006-58/advisory/","name":"http://secunia.com/secunia_research/2006-58/advisory/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Internet Explorer Script Error Handling Memory Corruption - Secunia Research - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-5579","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-5579","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"5579","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"internet_explorer","cpe6":"6","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"5579","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_server_2003","cpe6":"*","cpe7":"sp1","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T19:55:53.610Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_MISC","x_transferred"],"url":"http://secunia.com/secunia_research/2006-58/advisory/"},{"name":"ADV-2006-4966","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2006/4966"},{"name":"VU#599832","tags":["third-party-advisory","x_refsource_CERT-VN","x_transferred"],"url":"http://www.kb.cert.org/vuls/id/599832"},{"name":"TA06-346A","tags":["third-party-advisory","x_refsource_CERT","x_transferred"],"url":"http://www.us-cert.gov/cas/techalerts/TA06-346A.html"},{"name":"30813","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/30813"},{"name":"SSRT061288","tags":["vendor-advisory","x_refsource_HP","x_transferred"],"url":"http://www.securityfocus.com/archive/1/454969/100/200/threaded"},{"name":"HPSBST02180","tags":["vendor-advisory","x_refsource_HP","x_transferred"],"url":"http://www.securityfocus.com/archive/1/454969/100/200/threaded"},{"name":"MS06-072","tags":["vendor-advisory","x_refsource_MS","x_transferred"],"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-072"},{"name":"20061212 Secunia Research: Internet Explorer Script Error Handling MemoryCorruption","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/454205/100/0/threaded"},{"name":"21552","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/21552"},{"name":"oval:org.mitre.oval:def:761","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A761"},{"name":"20807","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/20807"},{"name":"1017373","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1017373"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2006-12-12T00:00:00.000Z","descriptions":[{"lang":"en","value":"Microsoft Internet Explorer 6 allows remote attackers to execute arbitrary code by using JavaScript to cause certain errors simultaneously, which results in the access of previously freed memory, aka \"Script Error Handling Memory Corruption Vulnerability.\""}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-17T20:57:01.000Z","orgId":"f38d906d-7342-40ea-92c1-6c4a2c6478c8","shortName":"microsoft"},"references":[{"tags":["x_refsource_MISC"],"url":"http://secunia.com/secunia_research/2006-58/advisory/"},{"name":"ADV-2006-4966","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2006/4966"},{"name":"VU#599832","tags":["third-party-advisory","x_refsource_CERT-VN"],"url":"http://www.kb.cert.org/vuls/id/599832"},{"name":"TA06-346A","tags":["third-party-advisory","x_refsource_CERT"],"url":"http://www.us-cert.gov/cas/techalerts/TA06-346A.html"},{"name":"30813","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/30813"},{"name":"SSRT061288","tags":["vendor-advisory","x_refsource_HP"],"url":"http://www.securityfocus.com/archive/1/454969/100/200/threaded"},{"name":"HPSBST02180","tags":["vendor-advisory","x_refsource_HP"],"url":"http://www.securityfocus.com/archive/1/454969/100/200/threaded"},{"name":"MS06-072","tags":["vendor-advisory","x_refsource_MS"],"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-072"},{"name":"20061212 Secunia Research: Internet Explorer Script Error Handling MemoryCorruption","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/454205/100/0/threaded"},{"name":"21552","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/21552"},{"name":"oval:org.mitre.oval:def:761","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A761"},{"name":"20807","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/20807"},{"name":"1017373","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1017373"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"secure@microsoft.com","ID":"CVE-2006-5579","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Microsoft Internet Explorer 6 allows remote attackers to execute arbitrary code by using JavaScript to cause certain errors simultaneously, which results in the access of previously freed memory, aka \"Script Error Handling Memory Corruption Vulnerability.\""}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://secunia.com/secunia_research/2006-58/advisory/","refsource":"MISC","url":"http://secunia.com/secunia_research/2006-58/advisory/"},{"name":"ADV-2006-4966","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2006/4966"},{"name":"VU#599832","refsource":"CERT-VN","url":"http://www.kb.cert.org/vuls/id/599832"},{"name":"TA06-346A","refsource":"CERT","url":"http://www.us-cert.gov/cas/techalerts/TA06-346A.html"},{"name":"30813","refsource":"OSVDB","url":"http://www.osvdb.org/30813"},{"name":"SSRT061288","refsource":"HP","url":"http://www.securityfocus.com/archive/1/454969/100/200/threaded"},{"name":"HPSBST02180","refsource":"HP","url":"http://www.securityfocus.com/archive/1/454969/100/200/threaded"},{"name":"MS06-072","refsource":"MS","url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-072"},{"name":"20061212 Secunia Research: Internet Explorer Script Error Handling MemoryCorruption","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/454205/100/0/threaded"},{"name":"21552","refsource":"BID","url":"http://www.securityfocus.com/bid/21552"},{"name":"oval:org.mitre.oval:def:761","refsource":"OVAL","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A761"},{"name":"20807","refsource":"SECUNIA","url":"http://secunia.com/advisories/20807"},{"name":"1017373","refsource":"SECTRACK","url":"http://securitytracker.com/id?1017373"}]}}}},"cveMetadata":{"assignerOrgId":"f38d906d-7342-40ea-92c1-6c4a2c6478c8","assignerShortName":"microsoft","cveId":"CVE-2006-5579","datePublished":"2006-12-12T20:00:00.000Z","dateReserved":"2006-10-27T00:00:00.000Z","dateUpdated":"2024-08-07T19:55:53.610Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2006-12-12 20:28:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-119","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":8.6,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":true,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_server_2003:*:sp1:*:*:*:*:*:*","matchCriteriaId":"DA778424-6F70-4AB6-ADD5-5D4664DFE463"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:internet_explorer:6:*:*:*:*:*:*:*","matchCriteriaId":"693D3C1C-E3E4-49DB-9A13-44ADDFF82507"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"5579","Ordinal":"1","Title":"CVE-2006-5579","CVE":"CVE-2006-5579","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"5579","Ordinal":"1","NoteData":"Microsoft Internet Explorer 6 allows remote attackers to execute arbitrary code by using JavaScript to cause certain errors simultaneously, which results in the access of previously freed memory, aka \"Script Error Handling Memory Corruption Vulnerability.\"","Type":"Description","Title":"CVE-2006-5579"},{"CveYear":"2006","CveId":"5579","Ordinal":"2","NoteData":"2006-12-12","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"5579","Ordinal":"3","NoteData":"2018-10-17","Type":"Other","Title":"Modified"}]}}}