peter bassill · operator
$ cve CVE-2006-0006 JSON

CVE-2006-0006 EXPLOIT

9.3
HIGH · CVSS 2.0 · EPSS 49.6% (pctl 99)

Patch early

A public exploit exists.

Description

Heap-based buffer overflow in the bitmap processing routine in Microsoft Windows Media Player 7.1 on Windows 2000 SP4, Media Player 9 on Windows 2000 SP4 and XP SP1, and Media Player 10 on XP SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted bitmap (.BMP) file that specifies a size of 0 but contains additional data.

Scoring

CVSS9.3 (HIGH, v2.0)
VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS49.56% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-119
On CISA KEVno
Public exploityes
Published2006-02-14
Last modified2026-06-16

Affected (7)

VendorProduct
microsoftwindows 2000
microsoftwindows 2003 server
microsoftwindows 98
microsoftwindows 98se
microsoftwindows me
microsoftwindows media player
microsoftwindows xp

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD