peter bassill · operator
$ cve CVE-2006-4495 JSON

CVE-2006-4495 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 20.7% (pctl 97)

Patch early

A public exploit exists.

Description

Microsoft Internet Explorer allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code by instantiating certain Windows 2000 ActiveX COM Objects including (1) ciodm.dll, (2) myinfo.dll, (3) msdxm.ocx, and (4) creator.dll.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS20.71% — more likely to be exploited than 97% of all CVEs
On CISA KEVno
Public exploityes
Published2006-08-31
Last modified2026-06-16

Affected (2)

VendorProduct
microsoftie
microsoftwindows 2003 server

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD