Back
CVE-2006-0020
An unspecified Microsoft WMF parsing application, as used in Internet Explorer 5.01 SP4 on Windows 2000 SP4, and 5.5 SP2 on Windows Millennium, and possibly other versions, allows attackers to cause a denial of service (crash) and possibly execute code via a crafted WMF file with a manipulated WMF header size, possibly involving an integer overflow, a different vulnerability than CVE-2005-4560, and aka "WMF Image Parsing Memory Corruption Vulnerability."
Published: Jan 10, 2006
Modified: Jun 16, 2026
CWE-189
CVSS Metrics
Affected Products (8)
| Vendor | Product | Version |
|---|---|---|
| microsoft | windows_2000 | * |
| microsoft | windows_2003_server | r2 |
| microsoft | windows_2003_server | sp1 |
| microsoft | windows_98 | * |
| microsoft | windows_98se | * |
| microsoft | windows_me | * |
| microsoft | windows_xp | * |
| microsoft | windows_xp | * |
GitHub Security Advisory GHSA-37h2-23m8-m8pm
An unspecified Microsoft WMF parsing application, as used in Internet Explorer 5.01 SP4 on...
References (22)
- http://linuxbox.org/pipermail/funsec/2006-January/002828.html Exploit, Vendor Advisory
- http://secunia.com/advisories/18729 Patch, Vendor Advisory
- http://secunia.com/advisories/18912 Vendor Advisory
- http://www.kb.cert.org/vuls/id/312956 Patch, Third Party Advisory, US Government Resource
- http://www.microsoft.com/technet/security/advisory/913333.mspx Vendor Advisory
- http://www.osvdb.org/22976
- http://www.securityfocus.com/bid/16516 Patch
- http://www.us-cert.gov/cas/techalerts/TA06-045A.html Third Party Advisory, US Government Resource
- http://www.vupen.com/english/advisories/2006/0469
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-004
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1638
- http://linuxbox.org/pipermail/funsec/2006-January/002828.html Exploit, Vendor Advisory
- http://secunia.com/advisories/18729 Patch, Vendor Advisory
- http://secunia.com/advisories/18912 Vendor Advisory
- http://www.kb.cert.org/vuls/id/312956 Patch, Third Party Advisory, US Government Resource
Risk Scores
CVSS Score
9.3 / 10
EPSS Score
19.06%
Top 3% most likely to be exploited
Threat Score
42.9 / 100
Data Sources
NVD
EPSS
GitHub