HIGH · 9.3

CVE-2006-0005

Buffer overflow in the plug-in for Microsoft Windows Media Player (WMP) 9 and 10, when used in browsers other than Internet Explorer and set as the default application to handle media files, allows re...

Vulnerability Description

Buffer overflow in the plug-in for Microsoft Windows Media Player (WMP) 9 and 10, when used in browsers other than Internet Explorer and set as the default application to handle media files, allows remote attackers to execute arbitrary code via HTML with an EMBED element containing a long src attribute.

CVSS Score

9.3

HIGH

AV:N/AC:M/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
MicrosoftWindows-Ntdatacenter_server
MicrosoftWindows 2000All versions
MicrosoftWindows 2000 Advanced ServerAll versions
MicrosoftWindows 2003 Serverdatacenter_edition
MicrosoftWindows Server 2000none
MicrosoftWindows Server 2003datacenter_sp1
MicrosoftWindows XpAll versions

Related Weaknesses (CWE)

References

FAQ

What is CVE-2006-0005?

CVE-2006-0005 is a vulnerability with a CVSS score of 9.3 (HIGH). Buffer overflow in the plug-in for Microsoft Windows Media Player (WMP) 9 and 10, when used in browsers other than Internet Explorer and set as the default application to handle media files, allows re...

How severe is CVE-2006-0005?

CVE-2006-0005 has been rated HIGH with a CVSS base score of 9.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2006-0005?

Check the references section above for vendor advisories and patch information. Affected products include: Microsoft Windows-Nt, Microsoft Windows 2000, Microsoft Windows 2000 Advanced Server, Microsoft Windows 2003 Server, Microsoft Windows Server 2000.