CVE-2006-3351

Windows Explorer <XP,2003 - Buffer Overflow

Title source: llm
STIX 2.1

Description

Buffer overflow in Windows Explorer (explorer.exe) on Windows XP and 2003 allows user-assisted attackers to cause a denial of service (repeated crash) and possibly execute arbitrary code via a .url file with an InternetShortcut tag containing a long URL and a large number of "file:" specifiers.

References (5)

Core 5
Core References
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/1186
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/439660/100/200/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/27567
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/439153/100/0/threaded
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/18838

Scores

EPSS 0.0693
EPSS Percentile 93.5%

Details

Status published
Products (16)
microsoft/windows_2003_server 3.1.0.3270
microsoft/windows_2003_server 64-bit
microsoft/windows_2003_server datacenter_64-bit sp1 (2 CPE variants)
microsoft/windows_2003_server datacenter_edition (3 CPE variants)
microsoft/windows_2003_server datacenter_edition_64-bit (3 CPE variants)
microsoft/windows_2003_server enterprise (3 CPE variants)
microsoft/windows_2003_server enterprise_64-bit (3 CPE variants)
microsoft/windows_2003_server enterprise_edition sp1 (2 CPE variants)
microsoft/windows_2003_server enterprise_edition_64-bit (3 CPE variants)
microsoft/windows_2003_server itanium
... and 6 more
Published Jul 06, 2006
Tracked Since Feb 18, 2026