{"api_version":"1","generated_at":"2026-07-23T06:02:26+00:00","cve":"CVE-2006-5745","urls":{"html":"https://cve.report/CVE-2006-5745","api":"https://cve.report/api/cve/CVE-2006-5745.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-5745","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-5745"},"summary":{"title":"CVE-2006-5745","description":"Unspecified vulnerability in the setRequestHeader method in the XMLHTTP (XML HTTP) ActiveX Control 4.0 in Microsoft XML Core Services 4.0 on Windows, when accessed by Internet Explorer, allows remote attackers to execute arbitrary code via crafted arguments that lead to memory corruption, a different vulnerability than CVE-2006-4685.  NOTE: some of these details are obtained from third party information.","state":"PUBLISHED","assigner":"mitre","published_at":"2006-11-06 18:07:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.6","severity":"","vector":"AV:N/AC:H/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:H/Au:N/C:C/I:C/A:C","baseScore":7.6,"accessVector":"NETWORK","accessComplexity":"HIGH","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://www.securityfocus.com/bid/20915","name":"http://www.securityfocus.com/bid/20915","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"Microsoft XML Core Service XMLHTTP ActiveX Control Remote Code Execution Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-071","name":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-071","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Microsoft Security Bulletin MS06-071 - Critical | Microsoft Docs","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.iss.net/threats/239.html","name":"http://www.iss.net/threats/239.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Microsoft XML HTTP Request Handling Vulnerability","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A104","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A104","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/30004","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/30004","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.kb.cert.org/vuls/id/585137","name":"http://www.kb.cert.org/vuls/id/585137","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["US Government Resource"],"title":"VU#585137 - Microsoft XML Core Services XMLHTTP ActiveX control vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/22687","name":"http://secunia.com/advisories/22687","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Microsoft XMLHTTP ActiveX Control Code Execution Vulnerability - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.exploit-db.com/exploits/2743","name":"https://www.exploit-db.com/exploits/2743","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Microsoft Internet Explorer 6/7 (XML Core Services) Remote Code Execution Exploit","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2006/4334","name":"http://www.vupen.com/english/advisories/2006/4334","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.microsoft.com/technet/security/advisory/927892.mspx","name":"http://www.microsoft.com/technet/security/advisory/927892.mspx","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Your request has been blocked. This could be\r\n                        due to several reasons.","mime":"text/html","httpstatus":"403","archivestatus":"200"},{"url":"http://xforce.iss.net/xforce/alerts/id/239","name":"http://xforce.iss.net/xforce/alerts/id/239","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Internet Security Systems -","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://securitytracker.com/id?1017157","name":"http://securitytracker.com/id?1017157","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityTracker.com Archives - Microsoft XML Core Services ActiveX Control Lets Remote Users Execute Arbitrary Code","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://blogs.securiteam.com/?p=717","name":"http://blogs.securiteam.com/?p=717","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecuriTeam Blogs » ActiveX - reason of the newest Windows 0-day, again","mime":"text/html","httpstatus":"401","archivestatus":"200"},{"url":"http://www.us-cert.gov/cas/techalerts/TA06-318A.html","name":"http://www.us-cert.gov/cas/techalerts/TA06-318A.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["US Government Resource"],"title":"US-CERT Technical Cyber Security Alert TA06-318A -- Microsoft Security Updates for Windows, Internet Explorer, and Adobe Flash","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-5745","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-5745","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"5745","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"xml_core_services","cpe6":"4.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T20:04:54.613Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"TA06-318A","tags":["third-party-advisory","x_refsource_CERT","x_transferred"],"url":"http://www.us-cert.gov/cas/techalerts/TA06-318A.html"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://xforce.iss.net/xforce/alerts/id/239"},{"name":"oval:org.mitre.oval:def:104","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A104"},{"name":"1017157","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1017157"},{"name":"2743","tags":["exploit","x_refsource_EXPLOIT-DB","x_transferred"],"url":"https://www.exploit-db.com/exploits/2743"},{"name":"20061104 Vulnerability in Microsoft XML HTTP Request Handling","tags":["third-party-advisory","x_refsource_ISS","x_transferred"],"url":"http://www.iss.net/threats/239.html"},{"name":"MS06-071","tags":["vendor-advisory","x_refsource_MS","x_transferred"],"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-071"},{"name":"ADV-2006-4334","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2006/4334"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://blogs.securiteam.com/?p=717"},{"name":"20915","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/20915"},{"name":"22687","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/22687"},{"name":"ie-xml-http-request-handling(30004)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/30004"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.microsoft.com/technet/security/advisory/927892.mspx"},{"name":"VU#585137","tags":["third-party-advisory","x_refsource_CERT-VN","x_transferred"],"url":"http://www.kb.cert.org/vuls/id/585137"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2006-11-03T00:00:00.000Z","descriptions":[{"lang":"en","value":"Unspecified vulnerability in the setRequestHeader method in the XMLHTTP (XML HTTP) ActiveX Control 4.0 in Microsoft XML Core Services 4.0 on Windows, when accessed by Internet Explorer, allows remote attackers to execute arbitrary code via crafted arguments that lead to memory corruption, a different vulnerability than CVE-2006-4685.  NOTE: some of these details are obtained from third party information."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-12T19:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"TA06-318A","tags":["third-party-advisory","x_refsource_CERT"],"url":"http://www.us-cert.gov/cas/techalerts/TA06-318A.html"},{"tags":["x_refsource_MISC"],"url":"http://xforce.iss.net/xforce/alerts/id/239"},{"name":"oval:org.mitre.oval:def:104","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A104"},{"name":"1017157","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1017157"},{"name":"2743","tags":["exploit","x_refsource_EXPLOIT-DB"],"url":"https://www.exploit-db.com/exploits/2743"},{"name":"20061104 Vulnerability in Microsoft XML HTTP Request Handling","tags":["third-party-advisory","x_refsource_ISS"],"url":"http://www.iss.net/threats/239.html"},{"name":"MS06-071","tags":["vendor-advisory","x_refsource_MS"],"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-071"},{"name":"ADV-2006-4334","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2006/4334"},{"tags":["x_refsource_MISC"],"url":"http://blogs.securiteam.com/?p=717"},{"name":"20915","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/20915"},{"name":"22687","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/22687"},{"name":"ie-xml-http-request-handling(30004)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/30004"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.microsoft.com/technet/security/advisory/927892.mspx"},{"name":"VU#585137","tags":["third-party-advisory","x_refsource_CERT-VN"],"url":"http://www.kb.cert.org/vuls/id/585137"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2006-5745","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Unspecified vulnerability in the setRequestHeader method in the XMLHTTP (XML HTTP) ActiveX Control 4.0 in Microsoft XML Core Services 4.0 on Windows, when accessed by Internet Explorer, allows remote attackers to execute arbitrary code via crafted arguments that lead to memory corruption, a different vulnerability than CVE-2006-4685.  NOTE: some of these details are obtained from third party information."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"TA06-318A","refsource":"CERT","url":"http://www.us-cert.gov/cas/techalerts/TA06-318A.html"},{"name":"http://xforce.iss.net/xforce/alerts/id/239","refsource":"MISC","url":"http://xforce.iss.net/xforce/alerts/id/239"},{"name":"oval:org.mitre.oval:def:104","refsource":"OVAL","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A104"},{"name":"1017157","refsource":"SECTRACK","url":"http://securitytracker.com/id?1017157"},{"name":"2743","refsource":"EXPLOIT-DB","url":"https://www.exploit-db.com/exploits/2743"},{"name":"20061104 Vulnerability in Microsoft XML HTTP Request Handling","refsource":"ISS","url":"http://www.iss.net/threats/239.html"},{"name":"MS06-071","refsource":"MS","url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-071"},{"name":"ADV-2006-4334","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2006/4334"},{"name":"http://blogs.securiteam.com/?p=717","refsource":"MISC","url":"http://blogs.securiteam.com/?p=717"},{"name":"20915","refsource":"BID","url":"http://www.securityfocus.com/bid/20915"},{"name":"22687","refsource":"SECUNIA","url":"http://secunia.com/advisories/22687"},{"name":"ie-xml-http-request-handling(30004)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/30004"},{"name":"http://www.microsoft.com/technet/security/advisory/927892.mspx","refsource":"CONFIRM","url":"http://www.microsoft.com/technet/security/advisory/927892.mspx"},{"name":"VU#585137","refsource":"CERT-VN","url":"http://www.kb.cert.org/vuls/id/585137"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2006-5745","datePublished":"2006-11-06T18:00:00.000Z","dateReserved":"2006-11-06T00:00:00.000Z","dateUpdated":"2024-08-07T20:04:54.613Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2006-11-06 18:07:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:H/Au:N/C:C/I:C/A:C","baseScore":7.6,"accessVector":"NETWORK","accessComplexity":"HIGH","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":4.9,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":true,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:xml_core_services:4.0:*:*:*:*:*:*:*","matchCriteriaId":"3C9B9BE3-6F83-469E-834F-3E00CFECD8E2"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"5745","Ordinal":"1","Title":"CVE-2006-5745","CVE":"CVE-2006-5745","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"5745","Ordinal":"1","NoteData":"Unspecified vulnerability in the setRequestHeader method in the XMLHTTP (XML HTTP) ActiveX Control 4.0 in Microsoft XML Core Services 4.0 on Windows, when accessed by Internet Explorer, allows remote attackers to execute arbitrary code via crafted arguments that lead to memory corruption, a different vulnerability than CVE-2006-4685.  NOTE: some of these details are obtained from third party information.","Type":"Description","Title":"CVE-2006-5745"},{"CveYear":"2006","CveId":"5745","Ordinal":"2","NoteData":"2006-11-06","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"5745","Ordinal":"3","NoteData":"2018-10-12","Type":"Other","Title":"Modified"}]}}}