{
    "id": "CVE-2006-0005",
    "published": "2006-02-14 19:06:00",
    "last_modified": "2026-06-16 22:19:41",
    "cvss_score": "9.3",
    "cvss_severity": "HIGH",
    "cvss_version": "2.0",
    "cvss_vector": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
    "cwe": "CWE-119",
    "description": "Buffer overflow in the plug-in for Microsoft Windows Media Player (WMP) 9 and 10, when used in browsers other than Internet Explorer and set as the default application to handle media files, allows remote attackers to execute arbitrary code via HTML with an EMBED element containing a long src attribute.",
    "epss_score": "0.38666",
    "epss_percentile": "0.98534",
    "kev": 0,
    "kev_due": null,
    "has_exploit": 1,
    "updated_at": "2026-09-26 18:15:01",
    "priority": {
        "rank": 2,
        "label": "Patch early",
        "why": "A public exploit exists."
    },
    "products": [
        {
            "vendor": "microsoft",
            "product": "windows_2000"
        },
        {
            "vendor": "microsoft",
            "product": "windows_2000_advanced_server"
        },
        {
            "vendor": "microsoft",
            "product": "windows_2003_server"
        },
        {
            "vendor": "microsoft",
            "product": "windows_server_2000"
        },
        {
            "vendor": "microsoft",
            "product": "windows_server_2003"
        },
        {
            "vendor": "microsoft",
            "product": "windows_xp"
        },
        {
            "vendor": "microsoft",
            "product": "windows-nt"
        }
    ],
    "kev_detail": null,
    "exploits": [
        {
            "source": "exploit-db",
            "ref_id": "1520",
            "title": "Microsoft Windows Media Player - Plugin Overflow (MS06-006) (3)",
            "date": "2006-02-22",
            "url": "https://www.exploit-db.com/exploits/1520"
        },
        {
            "source": "exploit-db",
            "ref_id": "1504",
            "title": "Microsoft Windows Media Player 9 - Plugin Overflow (MS06-006) (Metasploit)",
            "date": "2006-02-17",
            "url": "https://www.exploit-db.com/exploits/1504"
        },
        {
            "source": "exploit-db",
            "ref_id": "1505",
            "title": "Microsoft Windows Media Player 10 - Plugin Overflow (MS06-006)",
            "date": "2006-02-17",
            "url": "https://www.exploit-db.com/exploits/1505"
        }
    ],
    "refs_list": [
        "http://secunia.com/advisories/18852",
        "http://securitytracker.com/id?1015628",
        "http://www.idefense.com/intelligence/vulnerabilities/display.php?id=393",
        "http://www.kb.cert.org/vuls/id/692060",
        "http://www.securityfocus.com/bid/16644",
        "http://www.us-cert.gov/cas/techalerts/TA06-045A.html",
        "http://www.vupen.com/english/advisories/2006/0575",
        "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-006",
        "https://exchange.xforce.ibmcloud.com/vulnerabilities/24493",
        "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1559",
        "http://secunia.com/advisories/18852",
        "http://securitytracker.com/id?1015628",
        "http://www.idefense.com/intelligence/vulnerabilities/display.php?id=393",
        "http://www.kb.cert.org/vuls/id/692060",
        "http://www.securityfocus.com/bid/16644",
        "http://www.us-cert.gov/cas/techalerts/TA06-045A.html",
        "http://www.vupen.com/english/advisories/2006/0575",
        "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-006",
        "https://exchange.xforce.ibmcloud.com/vulnerabilities/24493",
        "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1559"
    ]
}