Heap-based buffer overflow in T2EMBED.DLL in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 up to SP1, Windows 98, and Windows ME allows remote attackers to execute arbitrary code via an e-mail message or web page with a crafted Embedded Open Type (EOT) web font that triggers the overflow during decompression.
References
Link Providers
https://www.spirityenterprise.com/managed-detection-response-microsoft spirity
https://www.spirityenterprise.com/pentest spirity
http://seclists.org/fulldisclosure/2006/Jan/363 cve-icon cve-icon
http://secunia.com/advisories/18311 cve-icon cve-icon
http://secunia.com/advisories/18365 cve-icon cve-icon
http://secunia.com/advisories/18391 cve-icon cve-icon
http://securitytracker.com/id?1015459 cve-icon cve-icon
http://support.avaya.com/elmodocs2/security/ASA-2006-004.htm cve-icon cve-icon
http://www.eeye.com/html/Research/Advisories/EEYEB20050801.html cve-icon cve-icon
http://www.kb.cert.org/vuls/id/915930 cve-icon cve-icon
http://www.osvdb.org/18829 cve-icon cve-icon
http://www.securityfocus.com/archive/1/421885/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/bid/16194 cve-icon cve-icon
http://www.us-cert.gov/cas/techalerts/TA06-010A.html cve-icon cve-icon
http://www.vupen.com/english/advisories/2006/0118 cve-icon cve-icon
http://www130.nortelnetworks.com/cgi-bin/eserv/cs/main.jsp?cscat=BLTNDETAIL&DocumentOID=375525 cve-icon cve-icon
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-002 cve-icon cve-icon
https://exchange.xforce.ibmcloud.com/vulnerabilities/23922 cve-icon cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1126 cve-icon cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1185 cve-icon cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1462 cve-icon cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1491 cve-icon cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A698 cve-icon cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A714 cve-icon cve-icon
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2024-08-07T16:18:20.632Z

Reserved: 2005-11-09T05:00:00.000Z

Link: CVE-2006-0010

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2006-01-10T22:03:00.000

Modified: 2025-04-03T01:03:51.193

Link: CVE-2006-0010

cve-icon Redhat

No data.