CVE-2006-1900 EXPLOIT
7.6
HIGH · CVSS 2.0 · EPSS 16.5% (pctl 97)
Patch early
A public exploit exists.
Description
Multiple buffer overflows in World Wide Web Consortium (W3C) Amaya 9.4, and possibly other versions including 8.x before 8.8.5, allow remote attackers to execute arbitrary code via a long value in (1) the COMPACT attribute of the COLGROUP element, (2) the ROWS attribute of the TEXTAREA element, and (3) the COLOR attribute of the LEGEND element; and via other unspecified attack vectors consisting of "dozens of possible snippets."
Scoring
| CVSS | 7.6 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:H/Au:N/C:C/I:C/A:C |
| EPSS | 16.55% — more likely to be exploited than 97% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2006-04-20 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| w3c | amaya |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | W3C Amaya 9.4 - textarea rows Attribute Value Overflow | 2006-04-13 |
| exploit-db | W3C Amaya 9.4 - legend color Attribute Value Overflow | 2006-04-13 |
References
- http://morph3us.org/advisories/20060412-amaya-94-2.txt
- http://morph3us.org/advisories/20060412-amaya-94.txt
- http://secunia.com/advisories/19670
- http://www.osvdb.org/24623
- http://www.osvdb.org/24624
- http://www.securityfocus.com/archive/1/430877/100/0/threaded
- http://www.securityfocus.com/archive/1/430879/100/0/threaded
- http://www.securityfocus.com/bid/17507
- http://www.vupen.com/english/advisories/2006/1351
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25791
- http://morph3us.org/advisories/20060412-amaya-94-2.txt
- http://morph3us.org/advisories/20060412-amaya-94.txt
- http://secunia.com/advisories/19670
- http://www.osvdb.org/24623
- http://www.osvdb.org/24624
- http://www.securityfocus.com/archive/1/430877/100/0/threaded
- http://www.securityfocus.com/archive/1/430879/100/0/threaded
- http://www.securityfocus.com/bid/17507
- http://www.vupen.com/english/advisories/2006/1351
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25791
→ the Explorer · watch your stack · NVD