Heap-based buffer overflow in T2EMBED.DLL in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 up to SP1, Windows 98, and Windows ME allows remote attackers to execute arbitrary code via an e-mail message or web page with a crafted Embedded Open Type (EOT) web font that triggers the overflow during decompression
Published Jan 10, 2006
9.3
HIGHCVSS 2.0
EPSS 33.08%
Description
Heap-based buffer overflow in T2EMBED.DLL in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 up to SP1, Windows 98, and Windows ME allows remote attackers to execute arbitrary code via an e-mail message or web page with a crafted Embedded Open Type (EOT) web font that triggers the overflow during decompression.
Affected products
No data.
- n/a
- n/a
- n/a
- n/a
- n/a
- datacenter_64-bit
- enterprise
- enterprise
- enterprise_64-bit
- enterprise_64-bit
- r2
- r2
- r2
- standard
- standard
- standard_64-bit
- web
- web
- n/a
- n/a
- n/a
- 3.5.1
- 3.5.1
- 3.5.1
- 3.5.1
- 3.5.1
- 3.5.1
- 3.5.1
- 4.0
- 4.0
- 4.0
- 4.0
- 4.0
- 4.0
- 4.0
- 4.0
- 4.0
- 4.0
- 4.0
- 4.0
- 4.0
- 4.0
- 4.0
- 4.0
- 4.0
- 4.0
- 4.0
- 4.0
- 4.0
- 4.0
- 4.0
- 4.0
- 4.0
- 4.0
- 4.0
- 4.0
- 4.0
- 4.0
- 4.0
- 4.0
- 4.0
- 4.0
- 4.0
- 4.0
- 4.0
- 4.0
- 4.0
- 4.0
- 4.0
- 4.0
- 4.0
- 4.0
- 4.0
- 4.0
- 4.0
- 4.0
- 4.0
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:M/Au:N/C:C/I:C/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (15 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 33.08% (0.33080) | 98.32th | v5 (v2026.06.15) |
| Jun 15, 2026 | 33.08% (0.33080) | 98.14th | v5 (v2026.06.15) |
| Feb 8, 2026 | 49.82% (0.49817) | 97.73th | v4 (v2025.03.14) |
| Oct 23, 2025 | 62.02% (0.62017) | 98.25th | v4 (v2025.03.14) |
| Oct 8, 2025 | 56.80% (0.56796) | 98.00th | v4 (v2025.03.14) |
| Oct 1, 2025 | 62.69% (0.62688) | 98.33th | v4 (v2025.03.14) |
| Mar 19, 2025 | 67.40% (0.67399) | 98.41th | v4 (v2025.03.14) |
| Mar 17, 2025 | 69.93% (0.69930) | 98.56th | v4 (v2025.03.14) |
| Dec 17, 2024 | 83.86% (0.83862) | 98.69th | v3 (v2023.03.01) |
| May 1, 2024 | 79.17% (0.79173) | 98.24th | v3 (v2023.03.01) |
| Dec 1, 2023 | 62.34% (0.62337) | 97.51th | v3 (v2023.03.01) |
| Jul 23, 2023 | 55.41% (0.55414) | 97.17th | v3 (v2023.03.01) |
| Mar 7, 2023 | 54.53% (0.54531) | 97.03th | v3 (v2023.03.01) |
| Mar 6, 2023 | 39.29% (0.39294) | 98.02th | v2 (v2022.01.01) |
| Feb 4, 2022 | 39.29% (0.39294) | 97.33th | v2 (v2022.01.01) |
References (22)
- http://seclists.org/fulldisclosure/2006/Jan/363 mailing-listx_refsource_FULLDISC
- http://secunia.com/advisories/18311 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/18365 third-party-advisoryx_refsource_SECUNIAPatchVendor Advisory
- http://secunia.com/advisories/18391 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://securitytracker.com/id?1015459 vdb-entryx_refsource_SECTRACK
- http://support.avaya.com/elmodocs2/security/ASA-2006-004.htm x_refsource_CONFIRM
- http://www.eeye.com/html/Research/Advisories/EEYEB20050801.html third-party-advisoryx_refsource_EEYE
- http://www.kb.cert.org/vuls/id/915930 third-party-advisoryx_refsource_CERT-VNThird Party AdvisoryUS Government Resource
- http://www.osvdb.org/18829 vdb-entryx_refsource_OSVDB
- http://www.securityfocus.com/archive/1/421885/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/bid/16194 vdb-entryx_refsource_BIDPatch
- http://www.us-cert.gov/cas/techalerts/TA06-010A.html third-party-advisoryx_refsource_CERTUS Government Resource
- http://www.vupen.com/english/advisories/2006/0118 vdb-entryx_refsource_VUPEN
- http://www130.nortelnetworks.com/cgi-bin/eserv/cs/main.jsp?cscat=BLTNDETAIL&DocumentOID=375525 x_refsource_MISC
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-002 vendor-advisoryx_refsource_MS
- https://exchange.xforce.ibmcloud.com/vulnerabilities/23922 vdb-entryx_refsource_XF
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1126 vdb-entrysignaturex_refsource_OVAL
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1185 vdb-entrysignaturex_refsource_OVAL
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1462 vdb-entrysignaturex_refsource_OVAL
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1491 vdb-entrysignaturex_refsource_OVAL
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A698 vdb-entrysignaturex_refsource_OVAL
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A714 vdb-entrysignaturex_refsource_OVAL
Change history (0)
No recorded changes yet.