CVE
- Id
- 22800
- CVE No.
- CVE-2006-6696
- Status
- Candidate
- Description
- Double free vulnerability in Microsoft Windows 2000, XP, 2003, and Vista allows local users to gain privileges by calling the MessageBox function with a MB_SERVICE_NOTIFICATION message with crafted data, which sends a HardError message to Client/Server Runtime Server Subsystem (CSRSS) process, which is not properly handled when invoking the UserHardError and GetHardErrorText functions in WINSRV.DLL.
- Phase
- Assigned (20061221)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
Id | CVE Id | CVE No. | Reference | Actions |
---|---|---|---|---|
220426 | 22800 | CVE-2006-6696 | BUGTRAQ:20061221 Microsoft Windows XP/2003/Vista memory corruption 0day | View |
220427 | 22800 | CVE-2006-6696 | URL:http://www.securityfocus.com/archive/1/archive/1/455061/100/0/threaded | View |
220428 | 22800 | CVE-2006-6696 | BUGTRAQ:20061221 Re: [Full-disclosure] Microsoft Windows XP/2003/Vista memory corruption 0day | View |
220429 | 22800 | CVE-2006-6696 | URL:http://www.securityfocus.com/archive/1/archive/1/455104/100/0/threaded | View |
220430 | 22800 | CVE-2006-6696 | BUGTRAQ:20061221 Re: [Full-disclosure] Microsoft Windows XP/2003/Vista memorycorruption 0day | View |
220431 | 22800 | CVE-2006-6696 | URL:http://www.securityfocus.com/archive/1/archive/1/455088/100/0/threaded | View |
220432 | 22800 | CVE-2006-6696 | BUGTRAQ:20061222 Re: Re: [Full-disclosure] Microsoft Windows XP/2003/Vista memory corruption 0day | View |
220433 | 22800 | CVE-2006-6696 | URL:http://www.securityfocus.com/archive/1/archive/1/455158/100/0/threaded | View |
220434 | 22800 | CVE-2006-6696 | BUGTRAQ:20061230 csrss.exe double-free vulnerability - arbitrary DWORD overwrite exploit | View |
220435 | 22800 | CVE-2006-6696 | URL:http://www.securityfocus.com/archive/1/archive/1/455546/100/0/threaded | View |
220436 | 22800 | CVE-2006-6696 | FULLDISC:20061221 Microsoft Windows XP/2003/Vista memory corruption 0day | View |
220437 | 22800 | CVE-2006-6696 | URL:http://lists.grok.org.uk/pipermail/full-disclosure/2006-December/051394.html | View |
220438 | 22800 | CVE-2006-6696 | MISC:http://www.determina.com/security.research/vulnerabilities/csrss-harderror.html | View |
220439 | 22800 | CVE-2006-6696 | MISC:http://www.security.nnov.ru/Gnews944.html | View |
220440 | 22800 | CVE-2006-6696 | MISC:http://www.security.nnov.ru/files/messagebox.c | View |
220441 | 22800 | CVE-2006-6696 | MISC:http://groups.google.ca/group/microsoft.public.win32.programmer.kernel/browse_thread/thread/c5946bf40f227058/7bd7b5d66a4e5aff | View |
220442 | 22800 | CVE-2006-6696 | MISC:http://www.kuban.ru/forum_new/forum2/files/19124.html | View |
220443 | 22800 | CVE-2006-6696 | MISC:http://isc.sans.org/diary.php?n&storyid=1965 | View |
220444 | 22800 | CVE-2006-6696 | MISC:http://research.eeye.com/html/alerts/zeroday/20061215.html | View |
220445 | 22800 | CVE-2006-6696 | MILW0RM:2967 | View |
220446 | 22800 | CVE-2006-6696 | URL:http://milw0rm.com/exploits/2967 | View |
220447 | 22800 | CVE-2006-6696 | CONFIRM:http://blogs.technet.com/msrc/archive/2006/12/22/new-report-of-a-windows-vulnerability.aspx | View |
220448 | 22800 | CVE-2006-6696 | HP:HPSBST02208 | View |
220449 | 22800 | CVE-2006-6696 | URL:http://www.securityfocus.com/archive/1/archive/1/466331/100/200/threaded | View |
220450 | 22800 | CVE-2006-6696 | HP:SSRT071365 | View |
220451 | 22800 | CVE-2006-6696 | URL:http://www.securityfocus.com/archive/1/archive/1/466331/100/200/threaded | View |
220452 | 22800 | CVE-2006-6696 | MS:MS07-021 | View |
220453 | 22800 | CVE-2006-6696 | URL:http://www.microsoft.com/technet/security/bulletin/ms07-021.mspx | View |
220454 | 22800 | CVE-2006-6696 | BID:21688 | View |
220455 | 22800 | CVE-2006-6696 | URL:http://www.securityfocus.com/bid/21688 | View |
220456 | 22800 | CVE-2006-6696 | BID:23324 | View |
220457 | 22800 | CVE-2006-6696 | URL:http://www.securityfocus.com/bid/23324 | View |
220458 | 22800 | CVE-2006-6696 | VUPEN:ADV-2006-5120 | View |
220459 | 22800 | CVE-2006-6696 | URL:http://www.vupen.com/english/advisories/2006/5120 | View |
220460 | 22800 | CVE-2006-6696 | VUPEN:ADV-2007-1325 | View |
220461 | 22800 | CVE-2006-6696 | URL:http://www.vupen.com/english/advisories/2007/1325 | View |
220462 | 22800 | CVE-2006-6696 | OVAL:oval:org.mitre.oval:def:1816 | View |
220463 | 22800 | CVE-2006-6696 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1816 | View |
220464 | 22800 | CVE-2006-6696 | SECTRACK:1017433 | View |
220465 | 22800 | CVE-2006-6696 | URL:http://securitytracker.com/id?1017433 | View |
220466 | 22800 | CVE-2006-6696 | SECUNIA:23448 | View |
Related JVN
Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
---|---|---|---|---|---|---|---|---|---|
62653 | JVNDB-2005-000896 | GConf の gconfd におけるサービス運用妨害 (DoS) の脆弱性 | GConf の GConf daemon (gconfd) には、GCONF_GLOBAL_LOCKS が設定されていてもユーザ名ベースにしたディレクトリ名の配下にテンポラリファイルを作成するため、サービス運用妨害 (DoS) 状態となる脆弱性が存在します。 | CVE-2006-6698 | 22800 | 1.9 | http://jvndb.jvn.jp/ja/contents/2005/JVNDB-2005-000896.html | View |