peter bassill · operator
$ cve CVE-2006-4777 JSON

CVE-2006-4777 EXPLOIT

7.6
HIGH · CVSS 2.0 · EPSS 79.8% (pctl 100)

Patch early

A public exploit exists.

Description

Heap-based buffer overflow in the DirectAnimation Path Control (DirectAnimation.PathControl) COM object (daxctle.ocx) for Internet Explorer 6.0 SP1, on Chinese and possibly other Windows distributions, allows remote attackers to execute arbitrary code via unknown manipulations in arguments to the KeyFrame method, possibly related to an integer overflow, as demonstrated by daxctle2, and a different vulnerability than CVE-2006-4446.

Scoring

CVSS7.6 (HIGH, v2.0)
VectorAV:N/AC:H/Au:N/C:C/I:C/A:C
EPSS79.78% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-119
On CISA KEVno
Public exploityes
Published2006-09-14
Last modified2026-06-16

Affected (1)

VendorProduct
microsoftie

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD