Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2006-0005


Buffer overflow in the plug-in for Microsoft Windows Media Player (WMP) 9 and 10, when used in browsers other than Internet Explorer and set as the default application to handle media files, allows remote attackers to execute arbitrary code via HTML with an EMBED element containing a long src attribute.


Published

2006-02-14T19:06:00.000

Last Modified

2025-04-03T01:03:51.193

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 9.3 (HIGH)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:C/I:C/A:C

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

8.6

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-119

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System microsoft windows-nt datacenter_server Yes
Operating System microsoft windows-nt datacenter_server Yes
Operating System microsoft windows-nt datacenter_server Yes
Operating System microsoft windows-nt datacenter_server Yes
Operating System microsoft windows-nt datacenter_server Yes
Operating System microsoft windows-nt xp Yes
Operating System microsoft windows-nt xp_tablet_pc Yes
Operating System microsoft windows-nt xp_tablet_pc Yes
Operating System microsoft windows-nt xp_tablet_pc Yes
Operating System microsoft windows_2000 * Yes
Operating System microsoft windows_2000 * Yes
Operating System microsoft windows_2000 * Yes
Operating System microsoft windows_2000 * Yes
Operating System microsoft windows_2000 * Yes
Operating System microsoft windows_2000 - Yes
Operating System microsoft windows_2000_advanced_server * Yes
Operating System microsoft windows_2000_advanced_server sp1 Yes
Operating System microsoft windows_2000_advanced_server sp2 Yes
Operating System microsoft windows_2000_advanced_server sp3 Yes
Operating System microsoft windows_2000_advanced_server sp4 Yes
Operating System microsoft windows_2003_server datacenter_edition Yes
Operating System microsoft windows_2003_server datacenter_edition_64-bit Yes
Operating System microsoft windows_2003_server enterprise_edition Yes
Operating System microsoft windows_2003_server enterprise_edition_64-bit Yes
Operating System microsoft windows_2003_server standard Yes
Operating System microsoft windows_2003_server standard_64-bit Yes
Operating System microsoft windows_2003_server web_edition Yes
Operating System microsoft windows_server_2000 none Yes
Operating System microsoft windows_server_2000 sp1 Yes
Operating System microsoft windows_server_2000 sp2 Yes
Operating System microsoft windows_server_2000 sp3 Yes
Operating System microsoft windows_server_2003 datacenter_sp1 Yes
Operating System microsoft windows_server_2003 enterprise_sp1 Yes
Operating System microsoft windows_server_2003 standard_sp1 Yes
Operating System microsoft windows_server_2003 web_edition_sp1 Yes
Operating System microsoft windows_xp * Yes
Operating System microsoft windows_xp * Yes
Operating System microsoft windows_xp * Yes
Operating System microsoft windows_xp * Yes
Operating System microsoft windows_xp * Yes
Operating System microsoft windows_xp * Yes
Operating System microsoft windows_xp * Yes
Operating System microsoft windows_xp * Yes
Operating System microsoft windows_xp * Yes
Operating System microsoft windows_xp - Yes

References