Vulnerability Name: | CVE-2004-0206 (CCN-16556) | ||||||||||||||||||||||||||||||||
Assigned: | 2004-10-12 | ||||||||||||||||||||||||||||||||
Published: | 2004-10-12 | ||||||||||||||||||||||||||||||||
Updated: | 2018-10-12 | ||||||||||||||||||||||||||||||||
Summary: | Network Dynamic Data Exchange (NetDDE) services for Microsoft Windows 98, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows attackers to remotely execute arbitrary code or locally gain privileges via a malicious message or application that involves an "unchecked buffer," possibly a buffer overflow. | ||||||||||||||||||||||||||||||||
CVSS v3 Severity: | 5.9 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||||||||||||||||||||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||||||||||||||||||||||||||
Vulnerability Type: | CWE-Other | ||||||||||||||||||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||||||||||||||||||
References: | Source: CCN Type: BugTraq Mailing List, Wed Oct 13 2004 - 09:35:35 CDT Microsoft Windows NetDDE Service Buffer Overflow Source: MITRE Type: CNA CVE-2004-0206 Source: BUGTRAQ Type: UNKNOWN 20041013 Microsoft Windows NetDDE Service Buffer Overflow Source: CCN Type: SA12803 Microsoft Windows NetDDE Buffer Overflow Vulnerability Source: SECUNIA Type: UNKNOWN 12803 Source: CCN Type: CIAC Information Bulletin P-011 Microsoft Vulnerability in NetDDE Could Allow Remote Code Execution (841533) Source: CCN Type: US-CERT VU#640488 Microsoft Windows contains an unchecked buffer in the NetDDE services Source: CERT-VN Type: Patch, Third Party Advisory, US Government Resource VU#640488 Source: CCN Type: Microsoft Security Bulletin MS04-031 Vulnerability in NetDDE Could Allow Remote Code Execution (841533) Source: CCN Type: NGSSoftware Insight Security Research Advisory #NISR21012005 Microsoft NetDDE Service Unauthenticated Remote Buffer Overflow Source: BID Type: UNKNOWN 11372 Source: CCN Type: BID-11372 Microsoft Windows NetDDE Remote Buffer Overflow Vulnerability Source: MS Type: UNKNOWN MS04-031 Source: XF Type: UNKNOWN win-netdde-bo(16556) Source: XF Type: UNKNOWN win-netdde-bo(16556) Source: XF Type: UNKNOWN win-ms04031-patch(17657) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:1852 Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:2394 Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:3120 Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:3242 Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:4592 Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:5074 Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:6788 | ||||||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||
BACK |