CVE-2006-3890
Stack-based buffer overflow in the Sky Software FileView ActiveX control, as used in WinZip 10 before build 7245 and in certain other applications, allows remote attackers to execute arbitrary code via a long FilePattern attribute in a WZFILEVIEW…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 14.6%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
Stack-based buffer overflow in the Sky Software FileView ActiveX control, as used in WinZip 10 before build 7245 and in certain other applications, allows remote attackers to execute arbitrary code via a long FilePattern attribute in a WZFILEVIEW object, a different vulnerability than CVE-2006-5198.
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 14.57% probability · 96th percentile
- CISA KEV
- Not listed
- Affected
- sky software/fileview activex control · winzip/winzip
- Source
- cret@cert.org
References
- http://secunia.com/advisories/22891Exploit, Patch, Vendor Advisory
- http://www.kb.cert.org/vuls/id/225217Patch, US Government Resource
- http://www.securityfocus.com/archive/1/451566/100/0/threaded
- http://www.securityfocus.com/bid/21060Exploit, Patch
- http://www.securityfocus.com/bid/21108
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-067
- https://www.exploit-db.com/exploits/2785
- http://secunia.com/advisories/22891Exploit, Patch, Vendor Advisory
- http://www.kb.cert.org/vuls/id/225217Patch, US Government Resource
- http://www.securityfocus.com/archive/1/451566/100/0/threaded
- http://www.securityfocus.com/bid/21060Exploit, Patch
- http://www.securityfocus.com/bid/21108
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-067
- https://www.exploit-db.com/exploits/2785
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.