peter bassill · operator
$ cve CVE-2006-3890 JSON

CVE-2006-3890 EXPLOIT

9.3
HIGH · CVSS 2.0 · EPSS 14.6% (pctl 97)

Patch early

A public exploit exists.

Description

Stack-based buffer overflow in the Sky Software FileView ActiveX control, as used in WinZip 10 before build 7245 and in certain other applications, allows remote attackers to execute arbitrary code via a long FilePattern attribute in a WZFILEVIEW object, a different vulnerability than CVE-2006-5198.

Scoring

CVSS9.3 (HIGH, v2.0)
VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS14.57% — more likely to be exploited than 97% of all CVEs
On CISA KEVno
Public exploityes
Published2006-11-21
Last modified2026-06-16

Affected (2)

VendorProduct
sky softwarefileview activex control
winzipwinzip

Public exploits

SourceTitleDate
exploit-dbWinZip 10.0.7245 - FileView ActiveX Buffer Overflow (2)2007-03-06

References

→ the Explorer  ·  watch your stack  ·  NVD