CVE-2006-2376

Integer overflow in the PolyPolygon function in Graphics Rendering Engine on Microsoft Windows 98 and Me allows remote attackers to execute arbitrary code via a Windows Metafile (WMF) or EMF image with a sum of entries in the vertext counts array and number of polygons that triggers a heap-based buffer overflow.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:microsoft:windows_98:*:gold:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_98se:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_me:*:*:*:*:*:*:*:*

History

21 Nov 2024, 00:11

Type Values Removed Values Added
References () http://secunia.com/advisories/20631 - Patch, Vendor Advisory () http://secunia.com/advisories/20631 - Patch, Vendor Advisory
References () http://securityreason.com/securityalert/1094 - () http://securityreason.com/securityalert/1094 -
References () http://securitytracker.com/id?1016286 - () http://securitytracker.com/id?1016286 -
References () http://www.kb.cert.org/vuls/id/909508 - US Government Resource () http://www.kb.cert.org/vuls/id/909508 - US Government Resource
References () http://www.osvdb.org/26431 - () http://www.osvdb.org/26431 -
References () http://www.securityfocus.com/archive/1/436950/100/0/threaded - () http://www.securityfocus.com/archive/1/436950/100/0/threaded -
References () http://www.securityfocus.com/bid/18322 - () http://www.securityfocus.com/bid/18322 -
References () http://www.us-cert.gov/cas/techalerts/TA06-164A.html - US Government Resource () http://www.us-cert.gov/cas/techalerts/TA06-164A.html - US Government Resource
References () http://www.vupen.com/english/advisories/2006/2324 - Vendor Advisory () http://www.vupen.com/english/advisories/2006/2324 - Vendor Advisory
References () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-026 - () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-026 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/26815 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/26815 -

Information

Published : 2006-06-13 18:02

Updated : 2024-11-21 00:11


NVD link : CVE-2006-2376

Mitre link : CVE-2006-2376

CVE.ORG link : CVE-2006-2376


JSON object : View

Products Affected

microsoft

  • windows_98se
  • windows_98
  • windows_me
CWE
CWE-189

Numeric Errors