Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2006-6133


Stack-based buffer overflow in Visual Studio Crystal Reports for Microsoft Visual Studio .NET 2002 and 2002 SP1, .NET 2003 and 2003 SP1, and 2005 and 2005 SP1 (formerly Business Objects Crystal Reports XI Professional) allows user-assisted remote attackers to execute arbitrary code via a crafted RPT file.


Published

2006-11-28T01:07:00.000

Last Modified

2025-04-09T00:30:58.490

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 7.6 (HIGH)

CVSSv2 Vector

AV:N/AC:H/Au:N/C:C/I:C/A:C

  • Access Vector: NETWORK
  • Access Complexity: HIGH
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

4.9

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-119

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application businessobjects crystal_reports_xi * Yes
Application microsoft visual_studio_.net 2002 Yes
Application microsoft visual_studio_.net 2002 Yes
Application microsoft visual_studio_.net 2003 Yes
Application microsoft visual_studio_.net 2003 Yes
Application microsoft visual_studio_.net 2005 Yes
Application microsoft visual_studio_.net 2005 Yes

References