Back

CVE-2006-0020

An unspecified Microsoft WMF parsing application, as used in Internet Explorer 5.01 SP4 on Windows 2000 SP4, and 5.5 SP2 on Windows Millennium, and possibly other versions, allows attackers to cause a denial of service (crash) and possibly execute code via a crafted WMF file with a manipulated WMF header size, possibly involving an integer overflow, a different vulnerability than CVE-2005-4560, and aka "WMF Image Parsing Memory Corruption Vulnerability."

Published: Jan 10, 2006 Modified: Jun 16, 2026
CWE-189

CVSS Metrics

Affected Products (8)

Vendor Product Version
microsoft windows_2000 *
microsoft windows_2003_server r2
microsoft windows_2003_server sp1
microsoft windows_98 *
microsoft windows_98se *
microsoft windows_me *
microsoft windows_xp *
microsoft windows_xp *

GitHub Security Advisory GHSA-37h2-23m8-m8pm

An unspecified Microsoft WMF parsing application, as used in Internet Explorer 5.01 SP4 on...

Risk Scores

CVSS Score 9.3 / 10
EPSS Score 19.06%

Top 3% most likely to be exploited

Threat Score 42.9 / 100

Data Sources

NVD EPSS GitHub