TROYANOSYVIRUS
Back to CVEs

CVE-2006-3086

N/A

Description

Stack-based buffer overflow in the HrShellOpenWithMonikerDisplayName function in Microsoft Hyperlink Object Library (hlink.dll) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long hyperlink, as demonstrated using an Excel worksheet with a long link in Unicode, aka "Hyperlink COM Object Buffer Overflow Vulnerability." NOTE: this is a different issue than CVE-2006-3059.

CVE Details

CVSS v3.1 ScoreN/A
Published6/19/2006
Last Modified4/16/2026
Sourcenvd
Honeypot Sightings0

Affected Products

microsoft:hyperlink_object_library

Weaknesses (CWE)

CWE-119

References

http://marc.info/?l=full-disclosure&m=115067840426070&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/20748(af854a3a-2127-422b-91ae-364da2661108)
http://securitytracker.com/id?1016339(af854a3a-2127-422b-91ae-364da2661108)
http://www.kb.cert.org/vuls/id/394444(af854a3a-2127-422b-91ae-364da2661108)
http://www.osvdb.org/26666(af854a3a-2127-422b-91ae-364da2661108)
http://www.securityfocus.com/bid/18500(af854a3a-2127-422b-91ae-364da2661108)
http://www.vupen.com/english/advisories/2006/2431(af854a3a-2127-422b-91ae-364da2661108)

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.