CVE-2006-6442
Last modified
CVE-2006-6442 is a vulnerability of currently unknown severity. Stack-based buffer overflow in the SetClientInfo function in the CDDBControlAOL.CDDBAOLControl ActiveX control (cddbcontrol.dll), as used in America Online (AOL) 7.0 4114.563, 8.0 4129.230, and 9.0 Security Edition 4156.910, and possibly other products, allows remote attackers to execute arbitrary code via a long ClientId argument.. EPSS estimates a 5.39% chance of exploitation in the next 30 days.
Description
Stack-based buffer overflow in the SetClientInfo function in the CDDBControlAOL.CDDBAOLControl ActiveX control (cddbcontrol.dll), as used in America Online (AOL) 7.0 4114.563, 8.0 4129.230, and 9.0 Security Edition 4156.910, and possibly other products, allows remote attackers to execute arbitrary code via a long ClientId argument.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Aol | Aol Client Software | 7.0_4114.563 |
| Aol | Aol Client Software | 8.0_4129.230 |
| Aol | Aol Client Software | 9.0 |
References
- http://secunia.com/advisories/23043Vendor Advisory
- http://secunia.com/secunia_research/2006-69/advisory/Vendor Advisory
- http://www.vupen.com/english/advisories/2006/4904Vendor Advisory
- http://secunia.com/advisories/23043Vendor Advisory
- http://secunia.com/secunia_research/2006-69/advisory/Vendor Advisory
- http://www.vupen.com/english/advisories/2006/4904Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2006-6442?
How severe is CVE-2006-6442?
How do I fix CVE-2006-6442?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2006
- CVE-2006-6436Cross-site scripting (XSS) vulnerability in the Network cont…
- CVE-2006-6437ops3-dmn in Xerox WorkCentre and WorkCentre Pro before 12.05…
- CVE-2006-6438Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13…
- CVE-2006-6439Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13…
- CVE-2006-6440Multiple unspecified vulnerabilities in Xerox WorkCentre and…
- CVE-2006-6441Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13…
- CVE-2006-6443Buffer overflow in the Novell Distributed Print Services (ND…
- CVE-2006-6444Stack-based buffer overflow in Nostra DivX Player 2.1, 2.2.0…
- CVE-2006-6445Directory traversal vulnerability in error.php in Envolution…
- CVE-2006-6446SQL injection vulnerability in index.php in iWare Profession…
- CVE-2006-6447Multiple cross-site scripting (XSS) vulnerabilities in Vt-Fo…
- CVE-2006-6448Multiple SQL injection vulnerabilities in Vt-Forum Lite 1.3 …
Are you affected by CVE-2006-6442?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
