2017-10-16 12:31:07 -04:00
{
2019-03-18 00:08:08 +00:00
"CVE_data_meta" : {
"ASSIGNER" : "cve@mitre.org" ,
"ID" : "CVE-2006-6696" ,
"STATE" : "PUBLIC"
} ,
"affects" : {
"vendor" : {
"vendor_data" : [
{
"product" : {
"product_data" : [
{
"product_name" : "n/a" ,
"version" : {
"version_data" : [
{
"version_value" : "n/a"
}
]
}
}
]
} ,
"vendor_name" : "n/a"
}
2017-10-16 12:31:07 -04:00
]
2019-03-18 00:08:08 +00:00
}
} ,
"data_format" : "MITRE" ,
"data_type" : "CVE" ,
"data_version" : "4.0" ,
"description" : {
"description_data" : [
{
"lang" : "eng" ,
"value" : "Double free vulnerability in Microsoft Windows 2000, XP, 2003, and Vista allows local users to gain privileges by calling the MessageBox function with a MB_SERVICE_NOTIFICATION message with crafted data, which sends a HardError message to Client/Server Runtime Server Subsystem (CSRSS) process, which is not properly handled when invoking the UserHardError and GetHardErrorText functions in WINSRV.DLL."
}
]
} ,
"problemtype" : {
"problemtype_data" : [
{
"description" : [
{
"lang" : "eng" ,
"value" : "n/a"
}
]
}
]
} ,
"references" : {
"reference_data" : [
{
"name" : "http://www.kuban.ru/forum_new/forum2/files/19124.html" ,
"refsource" : "MISC" ,
"url" : "http://www.kuban.ru/forum_new/forum2/files/19124.html"
} ,
{
"name" : "20061230 csrss.exe double-free vulnerability - arbitrary DWORD overwrite exploit" ,
"refsource" : "BUGTRAQ" ,
"url" : "http://www.securityfocus.com/archive/1/455546/100/0/threaded"
} ,
{
"name" : "HPSBST02208" ,
"refsource" : "HP" ,
"url" : "http://www.securityfocus.com/archive/1/466331/100/200/threaded"
} ,
{
"name" : "1017433" ,
"refsource" : "SECTRACK" ,
"url" : "http://securitytracker.com/id?1017433"
} ,
{
"name" : "http://groups.google.ca/group/microsoft.public.win32.programmer.kernel/browse_thread/thread/c5946bf40f227058/7bd7b5d66a4e5aff" ,
"refsource" : "MISC" ,
"url" : "http://groups.google.ca/group/microsoft.public.win32.programmer.kernel/browse_thread/thread/c5946bf40f227058/7bd7b5d66a4e5aff"
} ,
{
"name" : "http://www.security.nnov.ru/Gnews944.html" ,
"refsource" : "MISC" ,
"url" : "http://www.security.nnov.ru/Gnews944.html"
} ,
{
"name" : "http://research.eeye.com/html/alerts/zeroday/20061215.html" ,
"refsource" : "MISC" ,
"url" : "http://research.eeye.com/html/alerts/zeroday/20061215.html"
} ,
{
"name" : "http://www.determina.com/security.research/vulnerabilities/csrss-harderror.html" ,
"refsource" : "MISC" ,
"url" : "http://www.determina.com/security.research/vulnerabilities/csrss-harderror.html"
} ,
{
"name" : "20061221 Re: [Full-disclosure] Microsoft Windows XP/2003/Vista memorycorruption 0day" ,
"refsource" : "BUGTRAQ" ,
"url" : "http://www.securityfocus.com/archive/1/455088/100/0/threaded"
} ,
{
"name" : "http://blogs.technet.com/msrc/archive/2006/12/22/new-report-of-a-windows-vulnerability.aspx" ,
"refsource" : "CONFIRM" ,
"url" : "http://blogs.technet.com/msrc/archive/2006/12/22/new-report-of-a-windows-vulnerability.aspx"
} ,
{
"name" : "20061222 Re: Re: [Full-disclosure] Microsoft Windows XP/2003/Vista memory corruption 0day" ,
"refsource" : "BUGTRAQ" ,
"url" : "http://www.securityfocus.com/archive/1/455158/100/0/threaded"
} ,
{
"name" : "21688" ,
"refsource" : "BID" ,
"url" : "http://www.securityfocus.com/bid/21688"
} ,
{
"name" : "MS07-021" ,
"refsource" : "MS" ,
"url" : "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-021"
} ,
{
"name" : "oval:org.mitre.oval:def:1816" ,
"refsource" : "OVAL" ,
"url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1816"
} ,
{
"name" : "ADV-2007-1325" ,
"refsource" : "VUPEN" ,
"url" : "http://www.vupen.com/english/advisories/2007/1325"
} ,
{
"name" : "http://www.security.nnov.ru/files/messagebox.c" ,
"refsource" : "MISC" ,
"url" : "http://www.security.nnov.ru/files/messagebox.c"
} ,
{
"name" : "20061221 Microsoft Windows XP/2003/Vista memory corruption 0day" ,
"refsource" : "FULLDISC" ,
"url" : "http://lists.grok.org.uk/pipermail/full-disclosure/2006-December/051394.html"
} ,
{
"name" : "23324" ,
"refsource" : "BID" ,
"url" : "http://www.securityfocus.com/bid/23324"
} ,
{
"name" : "20061221 Re: [Full-disclosure] Microsoft Windows XP/2003/Vista memory corruption 0day" ,
"refsource" : "BUGTRAQ" ,
"url" : "http://www.securityfocus.com/archive/1/455104/100/0/threaded"
} ,
{
"name" : "20061221 Microsoft Windows XP/2003/Vista memory corruption 0day" ,
"refsource" : "BUGTRAQ" ,
"url" : "http://www.securityfocus.com/archive/1/455061/100/0/threaded"
} ,
{
"name" : "23448" ,
"refsource" : "SECUNIA" ,
"url" : "http://secunia.com/advisories/23448"
} ,
{
"name" : "SSRT071365" ,
"refsource" : "HP" ,
"url" : "http://www.securityfocus.com/archive/1/466331/100/200/threaded"
} ,
{
"name" : "http://isc.sans.org/diary.php?n&storyid=1965" ,
"refsource" : "MISC" ,
"url" : "http://isc.sans.org/diary.php?n&storyid=1965"
} ,
{
"name" : "ADV-2006-5120" ,
"refsource" : "VUPEN" ,
"url" : "http://www.vupen.com/english/advisories/2006/5120"
}
]
}
}