{"id": "CVE-2006-5559", "cveTags": [], "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "
[email protected]", "cvssData": {"version": "2.0", "baseScore": 9.3, "accessVector": "NETWORK", "vectorString": "AV:N/AC:M/Au:N/C:C/I:C/A:C", "authentication": "NONE", "integrityImpact": "COMPLETE", "accessComplexity": "MEDIUM", "availabilityImpact": "COMPLETE", "confidentialityImpact": "COMPLETE"}, "acInsufInfo": false, "impactScore": 10.0, "baseSeverity": "HIGH", "obtainAllPrivilege": true, "exploitabilityScore": 8.6, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": true}]}, "published": "2006-10-27T16:07:00.000", "references": [{"url": "http://blogs.technet.com/msrc/archive/2006/10/27/adodb-connection-poc-published.aspx", "source": "
[email protected]"}, {"url": "http://research.eeye.com/html/alerts/zeroday/20061027.html", "tags": ["Patch"], "source": "
[email protected]"}, {"url": "http://secunia.com/advisories/22452", "tags": ["Vendor Advisory"], "source": "
[email protected]"}, {"url": "http://securitytracker.com/id?1017127", "tags": ["Exploit", "Patch", "Vendor Advisory"], "source": "
[email protected]"}, {"url": "http://www.kb.cert.org/vuls/id/589272", "tags": ["Patch", "US Government Resource"], "source": "
[email protected]"}, {"url": "http://www.osvdb.org/31882", "source": "
[email protected]"}, {"url": "http://www.securityfocus.com/bid/20704", "tags": ["Exploit", "Patch"], "source": "
[email protected]"}, {"url": "http://www.us-cert.gov/cas/techalerts/TA07-044A.html", "tags": ["US Government Resource"], "source": "
[email protected]"}, {"url": "http://www.vupen.com/english/advisories/2007/0578", "tags": ["Vendor Advisory"], "source": "
[email protected]"}, {"url": "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-009", "source": "
[email protected]"}, {"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/29837", "source": "
[email protected]"}, {"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A214", "source": "
[email protected]"}, {"url": "http://blogs.technet.com/msrc/archive/2006/10/27/adodb-connection-poc-published.aspx", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://research.eeye.com/html/alerts/zeroday/20061027.html", "tags": ["Patch"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://secunia.com/advisories/22452", "tags": ["Vendor Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://securitytracker.com/id?1017127", "tags": ["Exploit", "Patch", "Vendor Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.kb.cert.org/vuls/id/589272", "tags": ["Patch", "US Government Resource"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.osvdb.org/31882", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.securityfocus.com/bid/20704", "tags": ["Exploit", "Patch"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.us-cert.gov/cas/techalerts/TA07-044A.html", "tags": ["US Government Resource"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.vupen.com/english/advisories/2007/0578", "tags": ["Vendor Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-009", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/29837", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A214", "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Deferred", "weaknesses": [{"type": "Primary", "source": "
[email protected]", "description": [{"lang": "en", "value": "CWE-20"}]}], "descriptions": [{"lang": "en", "value": "The Execute method in the ADODB.Connection 2.7 and 2.8 ActiveX control objects (ADODB.Connection.2.7 and ADODB.Connection.2.8) in the Microsoft Data Access Components (MDAC) 2.5 SP3, 2.7 SP1, 2.8, and 2.8 SP1 does not properly track freed memory when the second argument is a BSTR, which allows remote attackers to cause a denial of service (Internet Explorer crash) and possibly execute arbitrary code via certain strings in the second and third arguments."}, {"lang": "es", "value": "El objeto de control ActiveX ADODB.Connection 2.7 (ADODB.Connection.2.7) permite a atacantes remotos provocar una denegaci\u00f3n de servicio (ca\u00edda de Internet Explorer) mediante argumentos largos para la funci\u00f3n Execute."}], "lastModified": "2025-04-09T00:30:58.490", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:microsoft:windows_2000:*:sp4:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "83E7C4A0-78CF-4B56-82BF-EC932BDD8ADF"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:microsoft:data_access_components:2.5:sp3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B901D0A6-2F68-4CAC-B985-6A2BA0A1705B"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:microsoft:windows_xp:*:sp2:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "9B339C33-8896-4896-88FF-88E74FDBC543"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:microsoft:data_access_components:2.8:sp1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "036C836C-6387-4DAC-96B2-94C979D236E8"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:microsoft:windows_2003_server:*:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "60EC86B8-5C8C-4873-B364-FB1F8EFE1CFF"}, {"criteria": "cpe:2.3:o:microsoft:windows_2003_server:itanium:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "0808041A-CE1A-433A-9C2B-019097CCFB0C"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:microsoft:data_access_components:2.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1F233914-2763-42E8-BCB9-E0D1186783E8"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:microsoft:windows_2000:*:sp4:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "83E7C4A0-78CF-4B56-82BF-EC932BDD8ADF"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:microsoft:data_access_components:2.7:sp1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "819DDAAF-D9A3-4540-B467-2A7233D36038"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:microsoft:windows_2000:*:sp4:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "83E7C4A0-78CF-4B56-82BF-EC932BDD8ADF"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:microsoft:data_access_components:2.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1F233914-2763-42E8-BCB9-E0D1186783E8"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:microsoft:windows_2000:*:sp4:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "83E7C4A0-78CF-4B56-82BF-EC932BDD8ADF"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:microsoft:data_access_components:2.8:sp1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "036C836C-6387-4DAC-96B2-94C979D236E8"}], "operator": "OR"}], "operator": "AND"}], "evaluatorImpact": "Failed exploit attempts will likely result in an application level denial-of-service condition.", "sourceIdentifier": "
[email protected]"}