CVE-2006-4686
8Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 29%
exploitation probability
29%top 2% of all CVEs
observed exploitation
nono source reports it
Buffer overflow in the Extensible Stylesheet Language Transformations (XSLT) processing in Microsoft XML Parser 2.6 and XML Core Services 3.0 through 6.0 allows remote attackers to execute arbitrary code via a crafted Web page.
Affected products
n/a · n/aReferences
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-061http://secunia.com/advisories/22333http://securitytracker.com/id?1017033https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A285http://www.kb.cert.org/vuls/id/562788http://www.osvdb.org/29426http://www.securityfocus.com/archive/1/449179/100/0/threadedhttp://www.securityfocus.com/bid/20338http://www.vupen.com/english/advisories/2006/3980