7.6
CVSSv2

CVE-2006-1900

Published: 20/04/2006 Updated: 18/10/2018
CVSS v2 Base Score: 7.6 | Impact Score: 10 | Exploitability Score: 4.9
VMScore: 770
Vector: AV:N/AC:H/Au:N/C:C/I:C/A:C

Vulnerability Summary

Multiple buffer overflows in World Wide Web Consortium (W3C) Amaya 9.4, and possibly other versions including 8.x prior to 8.8.5, allow remote malicious users to execute arbitrary code via a long value in (1) the COMPACT attribute of the COLGROUP element, (2) the ROWS attribute of the TEXTAREA element, and (3) the COLOR attribute of the LEGEND element; and via other unspecified attack vectors consisting of "dozens of possible snippets."

Vulnerable Product Search on Vulmon Subscribe to Product

w3c amaya 9.4

Exploits

source: wwwsecurityfocuscom/bid/17507/info W3C Amaya is susceptible to multiple remote buffer-overflow vulnerabilities These issues are due to the application's failure to properly bounds-check user-supplied data before copying it to insufficiently sized memory buffers Remote attackers may exploit this issue to execute arbitrary machin ...
source: wwwsecurityfocuscom/bid/17507/info W3C Amaya is susceptible to multiple remote buffer-overflow vulnerabilities These issues are due to the application's failure to properly bounds-check user-supplied data before copying it to insufficiently sized memory buffers Remote attackers may exploit this issue to execute arbitrary mach ...