Vulnerabilities > CVE-2006-1313 - Unspecified vulnerability in Microsoft products
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN microsoft
nessus
Summary
Microsoft JScript 5.1, 5.5, and 5.6 on Windows 2000 SP4, and 5.6 on Windows XP, Server 2003, Windows 98 and Windows Me, will "release objects early" in certain cases, which results in memory corruption and allows remote attackers to execute arbitrary code.
Vulnerable Configurations
Nessus
NASL family | Windows : Microsoft Bulletins |
NASL id | SMB_NT_MS06-023.NASL |
description | The remote host is running a version of Windows that contains a flaw in JScript. An attacker may be able to execute arbitrary code on the remote host by constructing a malicious JScript and enticing a victim to visit a website or view a specially crafted email message. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 21687 |
published | 2006-06-13 |
reporter | This script is Copyright (C) 2006-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/21687 |
title | MS06-023: Vulnerability in Microsoft JScript Could Allow Remote Code Execution (917344) |
code |
|
Oval
accepted 2012-12-31T04:00:05.397-05:00 class vulnerability contributors name Robert L. Hollis organization ThreatGuard, Inc. name Nate Przybyszewski organization The MITRE Corporation name Chandan S organization SecPod Technologies
description Microsoft JScript 5.1, 5.5, and 5.6 on Windows 2000 SP4, and 5.6 on Windows XP, Server 2003, Windows 98 and Windows Me, will "release objects early" in certain cases, which results in memory corruption and allows remote attackers to execute arbitrary code. family windows id oval:org.mitre.oval:def:1067 status accepted submitted 2006-06-14T09:55:00.000-04:00 title Microsoft JScript Memory Corruption Vulnerability version 68 accepted 2007-03-21T16:16:57.859-04:00 class vulnerability contributors name Robert L. Hollis organization ThreatGuard, Inc. name Anna Min organization BigFix, Inc name Nate Przybyszewski organization The MITRE Corporation name Sudhir Gandhe organization Telos name Shane Shaffer organization G2, Inc.
description Microsoft JScript 5.1, 5.5, and 5.6 on Windows 2000 SP4, and 5.6 on Windows XP, Server 2003, Windows 98 and Windows Me, will "release objects early" in certain cases, which results in memory corruption and allows remote attackers to execute arbitrary code. family windows id oval:org.mitre.oval:def:1644 status deprecated submitted 2006-06-14T09:55:00.000-04:00 title DEPRECATED: Microsoft JScript Memory Corruption Vulnerability (Win2K) version 68 accepted 2007-03-21T16:17:03.450-04:00 class vulnerability contributors name Robert L. Hollis organization ThreatGuard, Inc. name Anna Min organization BigFix, Inc name Nate Przybyszewski organization The MITRE Corporation name Sudhir Gandhe organization Telos name Shane Shaffer organization G2, Inc.
description Microsoft JScript 5.1, 5.5, and 5.6 on Windows 2000 SP4, and 5.6 on Windows XP, Server 2003, Windows 98 and Windows Me, will "release objects early" in certain cases, which results in memory corruption and allows remote attackers to execute arbitrary code. family windows id oval:org.mitre.oval:def:1785 status deprecated submitted 2006-06-14T09:55:00.000-04:00 title DEPRECATED: Microsoft JScript Memory Corruption Vulnerability (Win2K w/ JScript 5.6) version 68 accepted 2006-10-24T09:15:47.362-04:00 class vulnerability contributors name Robert L. Hollis organization ThreatGuard, Inc. name Nate Przybyszewski organization The MITRE Corporation
description Microsoft JScript 5.1, 5.5, and 5.6 on Windows 2000 SP4, and 5.6 on Windows XP, Server 2003, Windows 98 and Windows Me, will "release objects early" in certain cases, which results in memory corruption and allows remote attackers to execute arbitrary code. family windows id oval:org.mitre.oval:def:2003 status deprecated submitted 2006-06-14T09:55:00.000-04:00 title DEPRECATED: Microsoft JScript Memory Corruption Vulnerability (WinXP) version 65
References
- http://www.kb.cert.org/vuls/id/390044
- http://www.securityfocus.com/bid/18359
- http://secunia.com/advisories/20620
- http://www.us-cert.gov/cas/techalerts/TA06-164A.html
- http://securitytracker.com/id?1016283
- http://www.osvdb.org/26434
- http://www.vupen.com/english/advisories/2006/2321
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26805
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2003
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1785
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1644
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1067
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-023