CVE-2006-4262
Last modified
CVE-2006-4262 is a vulnerability of currently unknown severity. Multiple buffer overflows in cscope 15.5 and earlier allow user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via multiple vectors including (1) a long pathname that is not properly handled during file list parsing, (2) long pathnames that result from path variable expansion such as tilde expansion for the HOME environment variable, and (3) a long -f (aka reffile) command line argument.. EPSS estimates a 3.65% chance of exploitation in the next 30 days.
Description
Multiple buffer overflows in cscope 15.5 and earlier allow user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via multiple vectors including (1) a long pathname that is not properly handled during file list parsing, (2) long pathnames that result from path variable expansion such as tilde expansion for the HOME environment variable, and (3) a long -f (aka reffile) command line argument.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cscope | Cscope | <= 15.5 |
References
- http://secunia.com/advisories/21601Vendor Advisory
- http://secunia.com/advisories/22239Vendor Advisory
- http://secunia.com/advisories/22515Vendor Advisory
- http://www.redhat.com/support/errata/RHSA-2009-1101.htmlVendor Advisory
- http://www.vupen.com/english/advisories/2006/3374Vendor Advisory
- https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=203645Patch, Vendor Advisory
- http://secunia.com/advisories/21601Vendor Advisory
- http://secunia.com/advisories/22239Vendor Advisory
- http://secunia.com/advisories/22515Vendor Advisory
- http://www.redhat.com/support/errata/RHSA-2009-1101.htmlVendor Advisory
- http://www.vupen.com/english/advisories/2006/3374Vendor Advisory
- https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=203645Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2006-4262?
How severe is CVE-2006-4262?
How do I fix CVE-2006-4262?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2006
- CVE-2006-4256index.php in Horde Application Framework before 3.1.2 allows…
- CVE-2006-4257IBM DB2 Universal Database (UDB) before 8.1 FixPak 13 allows…
- CVE-2006-4258Absolute path traversal vulnerability in the get functionali…
- CVE-2006-4259Cross-site scripting (XSS) vulnerability in index.php in Fot…
- CVE-2006-4260Directory traversal vulnerability in index.php in Fotopholde…
- CVE-2006-4261Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2006-4263Multiple PHP remote file inclusion vulnerabilities in the Pr…
- CVE-2006-4264Multiple PHP remote file inclusion vulnerabilities in the lm…9.8
- CVE-2006-4265Kaspersky Anti-Hacker 1.8.180, when Stealth Mode is enabled,…
- CVE-2006-4266Symantec Norton Personal Firewall 2006 9.1.0.33, and possibl…
- CVE-2006-4267Multiple SQL injection vulnerabilities in CubeCart 3.0.11 an…
- CVE-2006-4268Multiple cross-site scripting (XSS) vulnerabilities in CubeC…
Are you affected by CVE-2006-4262?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
