V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2006-4868
CVE
CriticalConfirmedExploit available

Stack-based buffer overflow in the Vector Graphics Rendering engine (vgx.dll), as used in Microsoft Outlook and Internet Explorer 6.0 on Wi…

CVSS
9.3
Critical
EPSS
0.62
p99
Published
2006-01-01
Updated
2006-01-01
Description

Stack-based buffer overflow in the Vector Graphics Rendering engine (vgx.dll), as used in Microsoft Outlook and Internet Explorer 6.0 on Windows XP SP2, and possibly other versions, allows remote attackers to execute arbitrary code via a Vector Markup Language (VML) file with a long fill parameter within a rect tag.

Tags · CWE
RCE
CWE-119
CAPEC-8
CAPEC-9
CAPEC-10
CAPEC-14
CAPEC-24
CAPEC-42
CAPEC-44
CAPEC-45
CAPEC-46
CAPEC-47
CAPEC-100
CAPEC-123
Affected products
Internet_explorerInternet_explorerOutlook
CVSS vector
AV:N/AC:M/Au:N/C:C/I:C/A:C
Timeline
2006-01-01
Published
2006-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: M
Medium
Authentication
Au: N
None (N)
Confidentiality Impact
C: C
Complete
Integrity Impact
I: C
Complete
Availability Impact
A: C
Complete
Exploit indicators
EPSS
0.621 · p99
Known exploited (KEV)
No
Known exploits — Сканер-ВС
16597
exploitdb · https://www.exploit-db.com/exploits/16597
Enterprise
2425
exploitdb · https://www.exploit-db.com/exploits/2425
Enterprise
2426
exploitdb · https://www.exploit-db.com/exploits/2426
Enterprise
Affected products
ProductVendorStatus
internet_explorer*Tracked
internet_explorer*Tracked
outlook*Tracked
Source databases
CVE