CVE-2006-2376
15Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 41%
exploitation probability
41%top 1% of all CVEs
observed exploitation
nono source reports it
Integer overflow in the PolyPolygon function in Graphics Rendering Engine on Microsoft Windows 98 and Me allows remote attackers to execute arbitrary code via a Windows Metafile (WMF) or EMF image with a sum of entries in the vertext counts array and number of polygons that triggers a heap-based buffer overflow.
Affected products
n/a · n/aReferences
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-026http://secunia.com/advisories/20631http://securityreason.com/securityalert/1094http://securitytracker.com/id?1016286https://exchange.xforce.ibmcloud.com/vulnerabilities/26815http://www.kb.cert.org/vuls/id/909508http://www.osvdb.org/26431http://www.securityfocus.com/archive/1/436950/100/0/threadedhttp://www.securityfocus.com/bid/18322http://www.us-cert.gov/cas/techalerts/TA06-164A.htmlhttp://www.vupen.com/english/advisories/2006/2324