CVE-2006-0005
Buffer overflow in the plug-in for Microsoft Windows Media Player (WMP) 9 and 10, when used in browsers other than Internet Explorer and set as the default application to handle media files, allows remote attackers to execute arbitrary code via HTML with an EMBED element containing a long src attribute.
- Affected products
- Internet Explorer, Windows Media Player
- Microsoft Windows-nt
- = datacenter_server, xp, xp_tablet_pc
- Microsoft Windows 2000
- All versions
- Microsoft Windows 2000 Advanced Server
- All versions
- Microsoft Windows 2003 Server
- = datacenter_edition, datacenter_edition_64-bit, enterprise_edition, enterprise_edition_64-bit, standard, standard_64-bit, web_edition
- Microsoft Windows Server 2000
- = none, SP1, SP2, SP3
- Microsoft Windows Server 2003
- = datacenter_sp1, enterprise_sp1, standard_sp1, web_edition_sp1
- Fix
- Available
- CVSS 2.0
- 9.3 HIGH
- EPSS
- 38.7% (98th percentile)
- Weakness
- CWE-119
- NVD status
- Modified
- Published
- 2006-02-14
CVE-2006-0005 at NVD
10 known exploits for CVE-2006-0005
Proof-of-concept code and exploit modules indexed by Sploitus
wmp_plugin_ms06_006.pm.txt
Microsoft Windows Media Player - Plugin Overflow (MS06-006) (3)
MS Windows Media Player 9 Plugin Overflow Expl (MS06-006) (meta)
Microsoft Windows Media Player 9 - Plugin Overflow (MS06-006) (Metasploit)
Microsoft Windows Media Player 9 - Plugin Overflow (MS06-006) (Metasploit)
Microsoft Windows Media Player 10 - Plugin Overflow (MS06-006)
Windows Media Player plugin EMBED buffer overflow
Windows Media Player plugin EMBED buffer overflow
Windows Media Player plugin EMBED buffer overflow
Windows Media Player plugin EMBED buffer overflow