CVE-2006-3086

Severity CVSS v4.0:
Pending analysis
Type:
CWE-119 Buffer Errors
Publication date:
19/06/2006
Last modified:
03/04/2025

Description

Stack-based buffer overflow in the HrShellOpenWithMonikerDisplayName function in Microsoft Hyperlink Object Library (hlink.dll) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long hyperlink, as demonstrated using an Excel worksheet with a long link in Unicode, aka "Hyperlink COM Object Buffer Overflow Vulnerability." NOTE: this is a different issue than CVE-2006-3059.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:microsoft:hyperlink_object_library:*:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools