Zero-friction vulnerability management platform

Mageni eases for you the vulnerability scanning, assessment, and management process. It is free and open-source.

Install Now

Available for macOS, Windows, and Linux

App screenshot

CVE-2006-0020

CVE information

Published

16 years ago

Last Modified

4 years ago

CVSSv2.0 Severity

High

Impact Analysis

Description

An unspecified Microsoft WMF parsing application, as used in Internet Explorer 5.01 SP4 on Windows 2000 SP4, and 5.5 SP2 on Windows Millennium, and possibly other versions, allows attackers to cause a denial of service (crash) and possibly execute code via a crafted WMF file with a manipulated WMF header size, possibly involving an integer overflow, a different vulnerability than CVE-2005-4560, and aka "WMF Image Parsing Memory Corruption Vulnerability.".

CVSSv2.0 Score

Severity
High
Base Score
9.3/10
Exploit Score
8.6/10
Access Vector
Network
Access Complexity
Medium
Authentication Required
None
Impact Score
10/10
Confidentiality Impact
Complete
Availability Impact
Complete
Integrity Impact
Complete

Products Affected

CPE Affected Vulnerable Excluding Edit
cpe:2.3:o:microsoft:windows_98se:*:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:microsoft:windows_xp:*:sp1:tablet_pc:*:*:*:*:*
  Yes
- -
cpe:2.3:o:microsoft:windows_2003_server:sp1:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:microsoft:windows_2003_server:r2:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:microsoft:windows_me:*:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:microsoft:windows_2000:*:sp4:*:fr:*:*:*:*
  Yes
- -
cpe:2.3:o:microsoft:windows_xp:*:sp2:tablet_pc:*:*:*:*:*
  Yes
- -
cpe:2.3:o:microsoft:windows_98:*:gold:*:*:*:*:*:*
  Yes
- -