CVE-2006-2378

Microsoft Windows ART Image Rendering - Remote Code Execution via Crafted ART Image

Title source: llm
STIX 2.1

Description

Buffer overflow in the ART Image Rendering component (jgdw400.dll) in Microsoft Windows XP SP1 and Sp2, Server 2003 SP1 and earlier, and Windows 98 and Me allows remote attackers to execute arbitrary code via a crafted ART image that causes heap corruption.

References (15)

Core 15
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/26809
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1640
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/26432
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1756
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1668
US Government Resource third-party-advisory x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA06-164A.html
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/20605
Patch, US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/923236
Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/18394
Various Sources third-party-advisory x_refsource_idefense
http://www.idefense.com/intelligence/vulnerabilities/display.php?id=407
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/2320
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1866
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1016292
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1590

Scores

EPSS 0.3479
EPSS Percentile 98.3%

Details

Status published
Products (14)
microsoft/ie 6.0 sp1
microsoft/internet_explorer 5.0.1 (5 CPE variants)
microsoft/internet_explorer 6.0
microsoft/windows_2003_server datacenter_edition (2 CPE variants)
microsoft/windows_2003_server datacenter_edition_64-bit (2 CPE variants)
microsoft/windows_2003_server enterprise_64-bit
microsoft/windows_2003_server enterprise_edition sp1
microsoft/windows_2003_server enterprise_edition_64-bit (2 CPE variants)
microsoft/windows_2003_server r2
microsoft/windows_2003_server sp1
... and 4 more
Published Jun 13, 2006
Tracked Since Feb 18, 2026