{"api_version":"1","generated_at":"2026-04-22T23:20:42+00:00","cve":"CVE-2006-6442","urls":{"html":"https://cve.report/CVE-2006-6442","api":"https://cve.report/api/cve/CVE-2006-6442.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-6442","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-6442"},"summary":{"title":"CVE-2006-6442","description":"Stack-based buffer overflow in the SetClientInfo function in the CDDBControlAOL.CDDBAOLControl ActiveX control (cddbcontrol.dll), as used in America Online (AOL) 7.0 4114.563, 8.0 4129.230, and 9.0 Security Edition 4156.910, and possibly other products, allows remote attackers to execute arbitrary code via a long ClientId argument.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2006-12-10 11:28:00","updated_at":"2018-10-17 21:48:00"},"problem_types":["CWE-119"],"metrics":[],"references":[{"url":"http://securitytracker.com/id?1017357","name":"1017357","refsource":"SECTRACK","tags":[],"title":"AOL Buffer Overflow in CDDBControl ActiveX Control Lets Remote Users Execute Arbitrary Code - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.grok.org.uk/pipermail/full-disclosure/2006-December/051230.html","name":"20061211 Secunia Research: AOL CDDBControl ActiveX Control \"SetClientInfo()\" Buffer Overflow","refsource":"FULLDISC","tags":[],"title":"[Full-disclosure] Secunia Research: AOL CDDBControl ActiveX\tControl\t\"SetClientInfo()\" Buffer Overflow","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/30790","name":"aol-cddbcontrol-bo(30790)","refsource":"XF","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2006/4904","name":"ADV-2006-4904","refsource":"VUPEN","tags":["Vendor Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/23043","name":"23043","refsource":"SECUNIA","tags":["Vendor Advisory"],"title":"AOL CDDBControl ActiveX Control \"SetClientInfo()\" Buffer Overflow - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/21488","name":"21488","refsource":"BID","tags":[],"title":"RETIRED: AOL CDDBControl ActiveX Control Buffer Overflow Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.securityfocus.com/archive/1/454105/100/0/threaded","name":"20061211 Secunia Research: AOL CDDBControl ActiveX Control\"SetClientInfo()\" Buffer Overflow","refsource":"BUGTRAQ","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/secunia_research/2006-69/advisory/","name":"http://secunia.com/secunia_research/2006-69/advisory/","refsource":"MISC","tags":["Vendor Advisory"],"title":"AOL CDDBControl ActiveX Control \"SetClientInfo()\" Buffer Overflow - Secunia Research - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://attrition.org/pipermail/vim/2006-December/001173.html","name":"20061211 GraceNote CDDBControl (CVE-2006-3134) = CDDBAOLControl (CVE-2006-6442)","refsource":"VIM","tags":[],"title":"[VIM] GraceNote CDDBControl (CVE-2006-3134) = CDDBAOLControl\t(CVE-2006-6442)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-6442","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-6442","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"6442","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"aol","cpe5":"aol_client_software","cpe6":"7.0_4114.563","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"6442","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"aol","cpe5":"aol_client_software","cpe6":"8.0_4129.230","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"6442","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"aol","cpe5":"aol_client_software","cpe6":"9.0","cpe7":"*","cpe8":"security_4156.910","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"6442","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"aol","cpe5":"aol_client_software","cpe6":"7.0_4114.563","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"6442","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"aol","cpe5":"aol_client_software","cpe6":"8.0_4129.230","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"6442","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"aol","cpe5":"aol_client_software","cpe6":"9.0","cpe7":"*","cpe8":"security_4156.910","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2006-6442","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Stack-based buffer overflow in the SetClientInfo function in the CDDBControlAOL.CDDBAOLControl ActiveX control (cddbcontrol.dll), as used in America Online (AOL) 7.0 4114.563, 8.0 4129.230, and 9.0 Security Edition 4156.910, and possibly other products, allows remote attackers to execute arbitrary code via a long ClientId argument."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"ADV-2006-4904","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2006/4904"},{"name":"21488","refsource":"BID","url":"http://www.securityfocus.com/bid/21488"},{"name":"20061211 Secunia Research: AOL CDDBControl ActiveX Control\"SetClientInfo()\" Buffer Overflow","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/454105/100/0/threaded"},{"name":"1017357","refsource":"SECTRACK","url":"http://securitytracker.com/id?1017357"},{"name":"23043","refsource":"SECUNIA","url":"http://secunia.com/advisories/23043"},{"name":"aol-cddbcontrol-bo(30790)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/30790"},{"name":"20061211 Secunia Research: AOL CDDBControl ActiveX Control \"SetClientInfo()\" Buffer Overflow","refsource":"FULLDISC","url":"http://lists.grok.org.uk/pipermail/full-disclosure/2006-December/051230.html"},{"name":"http://secunia.com/secunia_research/2006-69/advisory/","refsource":"MISC","url":"http://secunia.com/secunia_research/2006-69/advisory/"},{"name":"20061211 GraceNote CDDBControl (CVE-2006-3134) = CDDBAOLControl (CVE-2006-6442)","refsource":"VIM","url":"http://attrition.org/pipermail/vim/2006-December/001173.html"}]}},"nvd":{"publishedDate":"2006-12-10 11:28:00","lastModifiedDate":"2018-10-17 21:48:00","problem_types":["CWE-119"],"metrics":{"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE","baseScore":9.3},"severity":"HIGH","exploitabilityScore":8.6,"impactScore":10,"obtainAllPrivilege":true,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:aol:aol_client_software:7.0_4114.563:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:aol:aol_client_software:8.0_4129.230:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:aol:aol_client_software:9.0:*:security_4156.910:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"6442","Ordinal":"21794","Title":"CVE-2006-6442","CVE":"CVE-2006-6442","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"6442","Ordinal":"1","NoteData":"Stack-based buffer overflow in the SetClientInfo function in the CDDBControlAOL.CDDBAOLControl ActiveX control (cddbcontrol.dll), as used in America Online (AOL) 7.0 4114.563, 8.0 4129.230, and 9.0 Security Edition 4156.910, and possibly other products, allows remote attackers to execute arbitrary code via a long ClientId argument.","Type":"Description","Title":null},{"CveYear":"2006","CveId":"6442","Ordinal":"2","NoteData":"2006-12-10","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"6442","Ordinal":"3","NoteData":"2018-10-17","Type":"Other","Title":"Modified"}]}}}