CVE-2006-3730 - CVSS 8.8
CVE-2006-3730
Published Date:21 July, 2006CWE-94
Last modified:16 June, 2026
Link: CVE-2006-3730
NVD: CVE-2006-3730
UBUNTU: CVE-2006-3730
REDHAT: CVE-2006-3730
EUVD: EUVD-2006-3724
Last modified:16 June, 2026
Link: CVE-2006-3730
NVD: CVE-2006-3730
UBUNTU: CVE-2006-3730
REDHAT: CVE-2006-3730
EUVD: EUVD-2006-3724
Description
Integer overflow in Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a 0x7fffffff argument to the setSlice method on a WebViewFolderIcon ActiveX object, which leads to an invalid memory copy.
CVSS Base Score
BASE
8.8
High
CVSS scores for CVE-2006-3730
CVSS v3.1 : 8.8 HIGH
| Attack Vector | Network |
| Attack Complexity | Low |
| Privileges Required | None |
| Scope | Unchanged |
| Confidentiality Impact | High |
| Integrity Impact | High |
| Availability Impact | High |
| User Interaction | Required |
CVSS v2 : 9.3 HIGH
| Access Vector | Network |
| Access Complexity | Medium |
| Authentication | None |
| Confidentiality Impact | Complete |
| Integrity Impact | Complete |
| Availability Impact | Complete |
Threat Intelligence
- Has Public Exploit: Yes
- CISA KEV Release Date: N/A
- CISA KEV Due Date: N/A
- CISA KEV Required Action: N/A
Exploit Prediction in the next 30 days
63%
EPSS
Likely Exploited Vulnerabilities Probability
100%
LEV
Common Weakness Enumeration for CVE-2006-3730
CWE-94 : Improper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
Products affected by CVE-2006-3730
Configuration 1:
Running on ALL of the following:
Any of the following configurations:
ie
cpe:2.3:a:microsoft:ie:6.0:sp1:*:*:*:*:*:*
OR
internet_explorer
cpe:2.3:a:microsoft:internet_explorer:6.0:*:*:*:*:*:*:*
Running on:
windows_xp
cpe:2.3:o:microsoft:windows_xp:*:sp2:*:*:*:*:*:*
