CVE-2006-0010

CVSS V2 High 9.3 CVSS V3 None
Description
Heap-based buffer overflow in T2EMBED.DLL in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 up to SP1, Windows 98, and Windows ME allows remote attackers to execute arbitrary code via an e-mail message or web page with a crafted Embedded Open Type (EOT) web font that triggers the overflow during decompression.
Overview
  • CVE ID
  • CVE-2006-0010
  • Assigner
  • secure@microsoft.com
  • Vulnerability Status
  • Modified
  • Published Version
  • 2006-01-10T22:03:00
  • Last Modified Date
  • 2019-04-30T14:27:13
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:o:microsoft:windows_2000:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:o:microsoft:windows_2000:*:sp1:*:*:*:*:*:* 1 OR
cpe:2.3:o:microsoft:windows_2000:*:sp2:*:*:*:*:*:* 1 OR
cpe:2.3:o:microsoft:windows_2000:*:sp3:*:*:*:*:*:* 1 OR
cpe:2.3:o:microsoft:windows_2000:*:sp4:*:*:*:*:*:* 1 OR
cpe:2.3:o:microsoft:windows_2003_server:datacenter_64-bit:sp1:*:*:*:*:*:* 1 OR
cpe:2.3:o:microsoft:windows_2003_server:enterprise:*:64-bit:*:*:*:*:* 1 OR
cpe:2.3:o:microsoft:windows_2003_server:enterprise:sp1:*:*:*:*:*:* 1 OR
cpe:2.3:o:microsoft:windows_2003_server:enterprise_64-bit:*:*:*:*:*:*:* 1 OR
cpe:2.3:o:microsoft:windows_2003_server:enterprise_64-bit:sp1:*:*:*:*:*:* 1 OR
cpe:2.3:o:microsoft:windows_2003_server:r2:*:64-bit:*:*:*:*:* 1 OR
cpe:2.3:o:microsoft:windows_2003_server:r2:*:datacenter_64-bit:*:*:*:*:* 1 OR
cpe:2.3:o:microsoft:windows_2003_server:r2:sp1:*:*:*:*:*:* 1 OR
cpe:2.3:o:microsoft:windows_2003_server:standard:*:64-bit:*:*:*:*:* 1 OR
cpe:2.3:o:microsoft:windows_2003_server:standard:sp1:*:*:*:*:*:* 1 OR
cpe:2.3:o:microsoft:windows_2003_server:standard_64-bit:*:*:*:*:*:*:* 1 OR
cpe:2.3:o:microsoft:windows_2003_server:web:*:*:*:*:*:*:* 1 OR
cpe:2.3:o:microsoft:windows_2003_server:web:sp1:*:*:*:*:*:* 1 OR
cpe:2.3:o:microsoft:windows_98:*:gold:*:*:*:*:*:* 1 OR
cpe:2.3:o:microsoft:windows_98se:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:o:microsoft:windows_me:*:*:*:*:*:*:*:* 1 OR
cpe:2.3:o:microsoft:windows_nt:3.5.1:*:*:*:*:*:*:* 1 OR
cpe:2.3:o:microsoft:windows_nt:3.5.1:sp1:*:*:*:*:*:* 1 OR
cpe:2.3:o:microsoft:windows_nt:3.5.1:sp2:*:*:*:*:*:* 1 OR
cpe:2.3:o:microsoft:windows_nt:3.5.1:sp3:*:*:*:*:*:* 1 OR
cpe:2.3:o:microsoft:windows_nt:3.5.1:sp4:*:*:*:*:*:* 1 OR
cpe:2.3:o:microsoft:windows_nt:3.5.1:sp5:*:*:*:*:*:* 1 OR
cpe:2.3:o:microsoft:windows_nt:3.5.1:sp5:alpha:*:*:*:*:* 1 OR
cpe:2.3:o:microsoft:windows_nt:4.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:o:microsoft:windows_nt:4.0:*:alpha:*:*:*:*:* 1 OR
cpe:2.3:o:microsoft:windows_nt:4.0:*:enterprise_server:*:*:*:*:* 1 OR
cpe:2.3:o:microsoft:windows_nt:4.0:*:server:*:*:*:*:* 1 OR
cpe:2.3:o:microsoft:windows_nt:4.0:*:terminal_server:*:*:*:*:* 1 OR
cpe:2.3:o:microsoft:windows_nt:4.0:*:terminal_server_alpha:*:*:*:*:* 1 OR
cpe:2.3:o:microsoft:windows_nt:4.0:*:workstation:*:*:*:*:* 1 OR
cpe:2.3:o:microsoft:windows_nt:4.0:sp1:*:*:*:*:*:* 1 OR
cpe:2.3:o:microsoft:windows_nt:4.0:sp1:alpha:*:*:*:*:* 1 OR
cpe:2.3:o:microsoft:windows_nt:4.0:sp1:enterprise_server:*:*:*:*:* 1 OR
cpe:2.3:o:microsoft:windows_nt:4.0:sp1:server:*:*:*:*:* 1 OR
cpe:2.3:o:microsoft:windows_nt:4.0:sp1:terminal_server:*:*:*:*:* 1 OR
cpe:2.3:o:microsoft:windows_nt:4.0:sp1:workstation:*:*:*:*:* 1 OR
cpe:2.3:o:microsoft:windows_nt:4.0:sp2:*:*:*:*:*:* 1 OR
cpe:2.3:o:microsoft:windows_nt:4.0:sp2:alpha:*:*:*:*:* 1 OR
cpe:2.3:o:microsoft:windows_nt:4.0:sp2:enterprise_server:*:*:*:*:* 1 OR
cpe:2.3:o:microsoft:windows_nt:4.0:sp2:server:*:*:*:*:* 1 OR
cpe:2.3:o:microsoft:windows_nt:4.0:sp2:terminal_server:*:*:*:*:* 1 OR
cpe:2.3:o:microsoft:windows_nt:4.0:sp2:workstation:*:*:*:*:* 1 OR
cpe:2.3:o:microsoft:windows_nt:4.0:sp3:*:*:*:*:*:* 1 OR
cpe:2.3:o:microsoft:windows_nt:4.0:sp3:alpha:*:*:*:*:* 1 OR
cpe:2.3:o:microsoft:windows_nt:4.0:sp3:enterprise_server:*:*:*:*:* 1 OR
cpe:2.3:o:microsoft:windows_nt:4.0:sp3:server:*:*:*:*:* 1 OR
cpe:2.3:o:microsoft:windows_nt:4.0:sp3:terminal_server:*:*:*:*:* 1 OR
cpe:2.3:o:microsoft:windows_nt:4.0:sp3:workstation:*:*:*:*:* 1 OR
cpe:2.3:o:microsoft:windows_nt:4.0:sp4:*:*:*:*:*:* 1 OR
cpe:2.3:o:microsoft:windows_nt:4.0:sp4:alpha:*:*:*:*:* 1 OR
cpe:2.3:o:microsoft:windows_nt:4.0:sp4:enterprise_server:*:*:*:*:* 1 OR
cpe:2.3:o:microsoft:windows_nt:4.0:sp4:server:*:*:*:*:* 1 OR
cpe:2.3:o:microsoft:windows_nt:4.0:sp4:terminal_server:*:*:*:*:* 1 OR
cpe:2.3:o:microsoft:windows_nt:4.0:sp4:workstation:*:*:*:*:* 1 OR
cpe:2.3:o:microsoft:windows_nt:4.0:sp5:*:*:*:*:*:* 1 OR
cpe:2.3:o:microsoft:windows_nt:4.0:sp5:alpha:*:*:*:*:* 1 OR
cpe:2.3:o:microsoft:windows_nt:4.0:sp5:enterprise_server:*:*:*:*:* 1 OR
cpe:2.3:o:microsoft:windows_nt:4.0:sp5:server:*:*:*:*:* 1 OR
cpe:2.3:o:microsoft:windows_nt:4.0:sp5:terminal_server:*:*:*:*:* 1 OR
cpe:2.3:o:microsoft:windows_nt:4.0:sp5:workstation:*:*:*:*:* 1 OR
cpe:2.3:o:microsoft:windows_nt:4.0:sp6:*:*:*:*:*:* 1 OR
cpe:2.3:o:microsoft:windows_nt:4.0:sp6:alpha:*:*:*:*:* 1 OR
cpe:2.3:o:microsoft:windows_nt:4.0:sp6:enterprise_server:*:*:*:*:* 1 OR
cpe:2.3:o:microsoft:windows_nt:4.0:sp6:server:*:*:*:*:* 1 OR
cpe:2.3:o:microsoft:windows_nt:4.0:sp6:terminal_server:*:*:*:*:* 1 OR
cpe:2.3:o:microsoft:windows_nt:4.0:sp6:workstation:*:*:*:*:* 1 OR
cpe:2.3:o:microsoft:windows_nt:4.0:sp6a:*:*:*:*:*:* 1 OR
cpe:2.3:o:microsoft:windows_nt:4.0:sp6a:alpha:*:*:*:*:* 1 OR
cpe:2.3:o:microsoft:windows_nt:4.0:sp6a:enterprise_server:*:*:*:*:* 1 OR
cpe:2.3:o:microsoft:windows_nt:4.0:sp6a:server:*:*:*:*:* 1 OR
cpe:2.3:o:microsoft:windows_nt:4.0:sp6a:terminal_server:*:*:*:*:* 1 OR
cpe:2.3:o:microsoft:windows_nt:4.0:sp6a:workstation:*:*:*:*:* 1 OR
cpe:2.3:o:microsoft:windows_xp:*:*:64-bit:*:*:*:*:* 1 OR
cpe:2.3:o:microsoft:windows_xp:*:*:home:*:*:*:*:* 1 OR
cpe:2.3:o:microsoft:windows_xp:*:*:media_center:*:*:*:*:* 1 OR
cpe:2.3:o:microsoft:windows_xp:*:gold:professional:*:*:*:*:* 1 OR
cpe:2.3:o:microsoft:windows_xp:*:sp1:home:*:*:*:*:* 1 OR
cpe:2.3:o:microsoft:windows_xp:*:sp1:media_center:*:*:*:*:* 1 OR
cpe:2.3:o:microsoft:windows_xp:*:sp2:home:*:*:*:*:* 1 OR
cpe:2.3:o:microsoft:windows_xp:*:sp2:media_center:*:*:*:*:* 1 OR
cpe:2.3:o:microsoft:windows_xp:*:sp2:tablet_pc:*:*:*:*:* 1 OR
CVSS Version 2
  • Version
  • 2.0
  • Vector String
  • AV:N/AC:M/Au:N/C:C/I:C/A:C
  • Access Vector
  • NETWORK
  • Access Compatibility
  • MEDIUM
  • Authentication
  • NONE
  • Confidentiality Impact
  • COMPLETE
  • Integrity Impact
  • COMPLETE
  • Availability Impact
  • COMPLETE
  • Base Score
  • 9.3
  • Severity
  • HIGH
  • Exploitability Score
  • 8.6
  • Impact Score
  • 10
References
Reference URL Reference Tags
http://www.kb.cert.org/vuls/id/915930 Third Party Advisory US Government Resource
http://www.securityfocus.com/bid/16194 Patch
http://www.osvdb.org/18829
http://secunia.com/advisories/18365 Patch Vendor Advisory
http://www.us-cert.gov/cas/techalerts/TA06-010A.html US Government Resource
http://securitytracker.com/id?1015459
http://support.avaya.com/elmodocs2/security/ASA-2006-004.htm
http://secunia.com/advisories/18391 Vendor Advisory
http://secunia.com/advisories/18311 Vendor Advisory
http://www130.nortelnetworks.com/cgi-bin/eserv/cs/main.jsp?cscat=BLTNDETAIL&DocumentOID=375525
http://www.eeye.com/html/Research/Advisories/EEYEB20050801.html
http://www.vupen.com/english/advisories/2006/0118
http://seclists.org/fulldisclosure/2006/Jan/363
https://exchange.xforce.ibmcloud.com/vulnerabilities/23922
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A714
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A698
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1491
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1462
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1185
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1126
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-002
http://www.securityfocus.com/archive/1/421885/100/0/threaded
History
Created Old Value New Value Data Type Notes
2022-05-10 17:42:13 Added to TrackCVE