CVE-2006-0010

Heap-based buffer overflow in T2EMBED.DLL in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 up to SP1, Windows 98, and Windows ME allows remote attackers to execute arbitrary code via an e-mail message or web page with a crafted Embedded Open Type (EOT) web font that triggers the overflow during decompression.
References
Link Resource
http://seclists.org/fulldisclosure/2006/Jan/363
http://secunia.com/advisories/18311 Vendor Advisory
http://secunia.com/advisories/18365 Patch Vendor Advisory
http://secunia.com/advisories/18391 Vendor Advisory
http://securitytracker.com/id?1015459
http://support.avaya.com/elmodocs2/security/ASA-2006-004.htm
http://www.eeye.com/html/Research/Advisories/EEYEB20050801.html
http://www.kb.cert.org/vuls/id/915930 Third Party Advisory US Government Resource
http://www.osvdb.org/18829
http://www.securityfocus.com/archive/1/421885/100/0/threaded
http://www.securityfocus.com/bid/16194 Patch
http://www.us-cert.gov/cas/techalerts/TA06-010A.html US Government Resource
http://www.vupen.com/english/advisories/2006/0118
http://www130.nortelnetworks.com/cgi-bin/eserv/cs/main.jsp?cscat=BLTNDETAIL&DocumentOID=375525
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-002
https://exchange.xforce.ibmcloud.com/vulnerabilities/23922
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1126
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1185
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1462
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1491
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A698
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A714
http://seclists.org/fulldisclosure/2006/Jan/363
http://secunia.com/advisories/18311 Vendor Advisory
http://secunia.com/advisories/18365 Patch Vendor Advisory
http://secunia.com/advisories/18391 Vendor Advisory
http://securitytracker.com/id?1015459
http://support.avaya.com/elmodocs2/security/ASA-2006-004.htm
http://www.eeye.com/html/Research/Advisories/EEYEB20050801.html
http://www.kb.cert.org/vuls/id/915930 Third Party Advisory US Government Resource
http://www.osvdb.org/18829
http://www.securityfocus.com/archive/1/421885/100/0/threaded
http://www.securityfocus.com/bid/16194 Patch
http://www.us-cert.gov/cas/techalerts/TA06-010A.html US Government Resource
http://www.vupen.com/english/advisories/2006/0118
http://www130.nortelnetworks.com/cgi-bin/eserv/cs/main.jsp?cscat=BLTNDETAIL&DocumentOID=375525
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-002
https://exchange.xforce.ibmcloud.com/vulnerabilities/23922
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1126
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1185
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1462
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1491
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A698
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A714
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:microsoft:windows_2000:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2000:*:sp1:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2000:*:sp2:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2000:*:sp3:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2000:*:sp4:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2003_server:datacenter_64-bit:sp1:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2003_server:enterprise:*:64-bit:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2003_server:enterprise:sp1:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2003_server:enterprise_64-bit:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2003_server:enterprise_64-bit:sp1:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2003_server:r2:*:64-bit:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2003_server:r2:*:datacenter_64-bit:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2003_server:r2:sp1:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2003_server:standard:*:64-bit:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2003_server:standard:sp1:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2003_server:standard_64-bit:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2003_server:web:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2003_server:web:sp1:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_98:*:gold:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_98se:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_me:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_nt:3.5.1:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_nt:3.5.1:sp1:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_nt:3.5.1:sp2:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_nt:3.5.1:sp3:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_nt:3.5.1:sp4:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_nt:3.5.1:sp5:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_nt:3.5.1:sp5:alpha:*:*:*:*:*
cpe:2.3:o:microsoft:windows_nt:4.0:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_nt:4.0:*:alpha:*:*:*:*:*
cpe:2.3:o:microsoft:windows_nt:4.0:*:enterprise_server:*:*:*:*:*
cpe:2.3:o:microsoft:windows_nt:4.0:*:server:*:*:*:*:*
cpe:2.3:o:microsoft:windows_nt:4.0:*:terminal_server:*:*:*:*:*
cpe:2.3:o:microsoft:windows_nt:4.0:*:terminal_server_alpha:*:*:*:*:*
cpe:2.3:o:microsoft:windows_nt:4.0:*:workstation:*:*:*:*:*
cpe:2.3:o:microsoft:windows_nt:4.0:sp1:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_nt:4.0:sp1:alpha:*:*:*:*:*
cpe:2.3:o:microsoft:windows_nt:4.0:sp1:enterprise_server:*:*:*:*:*
cpe:2.3:o:microsoft:windows_nt:4.0:sp1:server:*:*:*:*:*
cpe:2.3:o:microsoft:windows_nt:4.0:sp1:terminal_server:*:*:*:*:*
cpe:2.3:o:microsoft:windows_nt:4.0:sp1:workstation:*:*:*:*:*
cpe:2.3:o:microsoft:windows_nt:4.0:sp2:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_nt:4.0:sp2:alpha:*:*:*:*:*
cpe:2.3:o:microsoft:windows_nt:4.0:sp2:enterprise_server:*:*:*:*:*
cpe:2.3:o:microsoft:windows_nt:4.0:sp2:server:*:*:*:*:*
cpe:2.3:o:microsoft:windows_nt:4.0:sp2:terminal_server:*:*:*:*:*
cpe:2.3:o:microsoft:windows_nt:4.0:sp2:workstation:*:*:*:*:*
cpe:2.3:o:microsoft:windows_nt:4.0:sp3:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_nt:4.0:sp3:alpha:*:*:*:*:*
cpe:2.3:o:microsoft:windows_nt:4.0:sp3:enterprise_server:*:*:*:*:*
cpe:2.3:o:microsoft:windows_nt:4.0:sp3:server:*:*:*:*:*
cpe:2.3:o:microsoft:windows_nt:4.0:sp3:terminal_server:*:*:*:*:*
cpe:2.3:o:microsoft:windows_nt:4.0:sp3:workstation:*:*:*:*:*
cpe:2.3:o:microsoft:windows_nt:4.0:sp4:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_nt:4.0:sp4:alpha:*:*:*:*:*
cpe:2.3:o:microsoft:windows_nt:4.0:sp4:enterprise_server:*:*:*:*:*
cpe:2.3:o:microsoft:windows_nt:4.0:sp4:server:*:*:*:*:*
cpe:2.3:o:microsoft:windows_nt:4.0:sp4:terminal_server:*:*:*:*:*
cpe:2.3:o:microsoft:windows_nt:4.0:sp4:workstation:*:*:*:*:*
cpe:2.3:o:microsoft:windows_nt:4.0:sp5:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_nt:4.0:sp5:alpha:*:*:*:*:*
cpe:2.3:o:microsoft:windows_nt:4.0:sp5:enterprise_server:*:*:*:*:*
cpe:2.3:o:microsoft:windows_nt:4.0:sp5:server:*:*:*:*:*
cpe:2.3:o:microsoft:windows_nt:4.0:sp5:terminal_server:*:*:*:*:*
cpe:2.3:o:microsoft:windows_nt:4.0:sp5:workstation:*:*:*:*:*
cpe:2.3:o:microsoft:windows_nt:4.0:sp6:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_nt:4.0:sp6:alpha:*:*:*:*:*
cpe:2.3:o:microsoft:windows_nt:4.0:sp6:enterprise_server:*:*:*:*:*
cpe:2.3:o:microsoft:windows_nt:4.0:sp6:server:*:*:*:*:*
cpe:2.3:o:microsoft:windows_nt:4.0:sp6:terminal_server:*:*:*:*:*
cpe:2.3:o:microsoft:windows_nt:4.0:sp6:workstation:*:*:*:*:*
cpe:2.3:o:microsoft:windows_nt:4.0:sp6a:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_nt:4.0:sp6a:alpha:*:*:*:*:*
cpe:2.3:o:microsoft:windows_nt:4.0:sp6a:enterprise_server:*:*:*:*:*
cpe:2.3:o:microsoft:windows_nt:4.0:sp6a:server:*:*:*:*:*
cpe:2.3:o:microsoft:windows_nt:4.0:sp6a:terminal_server:*:*:*:*:*
cpe:2.3:o:microsoft:windows_nt:4.0:sp6a:workstation:*:*:*:*:*
cpe:2.3:o:microsoft:windows_xp:*:*:64-bit:*:*:*:*:*
cpe:2.3:o:microsoft:windows_xp:*:*:home:*:*:*:*:*
cpe:2.3:o:microsoft:windows_xp:*:*:media_center:*:*:*:*:*
cpe:2.3:o:microsoft:windows_xp:*:gold:professional:*:*:*:*:*
cpe:2.3:o:microsoft:windows_xp:*:sp1:home:*:*:*:*:*
cpe:2.3:o:microsoft:windows_xp:*:sp1:media_center:*:*:*:*:*
cpe:2.3:o:microsoft:windows_xp:*:sp2:home:*:*:*:*:*
cpe:2.3:o:microsoft:windows_xp:*:sp2:media_center:*:*:*:*:*
cpe:2.3:o:microsoft:windows_xp:*:sp2:tablet_pc:*:*:*:*:*

History

21 Nov 2024, 00:05

Type Values Removed Values Added
References () http://seclists.org/fulldisclosure/2006/Jan/363 - () http://seclists.org/fulldisclosure/2006/Jan/363 -
References () http://secunia.com/advisories/18311 - Vendor Advisory () http://secunia.com/advisories/18311 - Vendor Advisory
References () http://secunia.com/advisories/18365 - Patch, Vendor Advisory () http://secunia.com/advisories/18365 - Patch, Vendor Advisory
References () http://secunia.com/advisories/18391 - Vendor Advisory () http://secunia.com/advisories/18391 - Vendor Advisory
References () http://securitytracker.com/id?1015459 - () http://securitytracker.com/id?1015459 -
References () http://support.avaya.com/elmodocs2/security/ASA-2006-004.htm - () http://support.avaya.com/elmodocs2/security/ASA-2006-004.htm -
References () http://www.eeye.com/html/Research/Advisories/EEYEB20050801.html - () http://www.eeye.com/html/Research/Advisories/EEYEB20050801.html -
References () http://www.kb.cert.org/vuls/id/915930 - Third Party Advisory, US Government Resource () http://www.kb.cert.org/vuls/id/915930 - Third Party Advisory, US Government Resource
References () http://www.osvdb.org/18829 - () http://www.osvdb.org/18829 -
References () http://www.securityfocus.com/archive/1/421885/100/0/threaded - () http://www.securityfocus.com/archive/1/421885/100/0/threaded -
References () http://www.securityfocus.com/bid/16194 - Patch () http://www.securityfocus.com/bid/16194 - Patch
References () http://www.us-cert.gov/cas/techalerts/TA06-010A.html - US Government Resource () http://www.us-cert.gov/cas/techalerts/TA06-010A.html - US Government Resource
References () http://www.vupen.com/english/advisories/2006/0118 - () http://www.vupen.com/english/advisories/2006/0118 -
References () http://www130.nortelnetworks.com/cgi-bin/eserv/cs/main.jsp?cscat=BLTNDETAIL&DocumentOID=375525 - () http://www130.nortelnetworks.com/cgi-bin/eserv/cs/main.jsp?cscat=BLTNDETAIL&DocumentOID=375525 -
References () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-002 - () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-002 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/23922 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/23922 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1126 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1126 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1185 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1185 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1462 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1462 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1491 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1491 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A698 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A698 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A714 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A714 -

Information

Published : 2006-01-10 22:03

Updated : 2024-11-21 00:05


NVD link : CVE-2006-0010

Mitre link : CVE-2006-0010

CVE.ORG link : CVE-2006-0010


JSON object : View

Products Affected

microsoft

  • windows_me
  • windows_98se
  • windows_2003_server
  • windows_xp
  • windows_2000
  • windows_nt
  • windows_98
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer