CVE-2006-0005

Severity CVSS v4.0:
Pending analysis
Type:
CWE-119 Buffer Errors
Publication date:
14/02/2006
Last modified:
03/04/2025

Description

Buffer overflow in the plug-in for Microsoft Windows Media Player (WMP) 9 and 10, when used in browsers other than Internet Explorer and set as the default application to handle media files, allows remote attackers to execute arbitrary code via HTML with an EMBED element containing a long src attribute.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:microsoft:windows-nt:datacenter_server:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows-nt:datacenter_server:sp1:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows-nt:datacenter_server:sp2:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows-nt:datacenter_server:sp3:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows-nt:datacenter_server:sp4:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows-nt:xp:sp2:home:*:*:*:*:*
cpe:2.3:o:microsoft:windows-nt:xp_tablet_pc:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows-nt:xp_tablet_pc:sp1:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows-nt:xp_tablet_pc:sp2:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2000:*:sp1:pro:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2000:*:sp2:pro:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2000:*:sp3:pro:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2000:*:sp4:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2000:*:sp4:pro:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2000:-:*:*:*:*:*:*:*