CVE detail
CVE-2006-2492
Buffer overflow in Microsoft Word in Office 2000 SP3, Office XP SP3, Office 2003 Sp1 and SP2, and Microsoft Works Suites through 2006, allows user-assisted attackers to execute arbitrary code via a malformed object pointer, as originally reported by ISC on 20060519 for a zero-day attack.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 11.0 · diversity 6.5 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
2 source links · newest first
- Find potential exploit conditions in Microsoft Office documentsHelp Net Security
OfficeCat is a command line utility developed by the Sourcefire VRT that can be used to process Microsoft Office Documents to determine the presence of potential exploit conditions in the file. Officecat is available for Windows and Linux. Vulnerabilities checked by OfficeCat: CVE-2006-0001 CVE-2006-1301 CVE-2006-1306 CVE-2006-1308 CVE-2006-1540 CVE-2006-2492 CVE-2006-3014 CVE-2006-3086 CVE-2006-3431 CVE-2006-3432 CVE-2006-3493 CVE-2006-3590 CVE-2006-3656 CVE-2006-3864 CVE-2006-3865 CVE-2006-3875 CVE-2006-3876 CVE-2006-3877 CVE-2006-4534 CVE-2006-4694 CVE-2006-4700 CVE-2006-4701 CVE-2006-5994 CVE-2006-5995 CVE-2006-6456 CVE-2006-6561 CVE-2007-0027 CVE-2007-0030 CVE-2007-0031 CVE-2007-0515 CVE-2007-0671 CVE-2007-1203 CVE-2007-1214 … More →
newswww.helpnetsecurity.comNov 2, 2009, 3:02 PM Fake security software programs along with attacks using vulnerabilities in applications continued to pester Internet users in the last half of 2008, according to Microsoft’s latest security report. The bogus security software programs often offer a free scan that falsely says a user’s computer is infected. If installed, the programs are ineffective against malicious software. […]
newswww.csoonline.comApr 9, 2009, 3:00 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2013-1331CVSS 7.8 · High
Buffer overflow in Microsoft Office 2003 SP3 and Office 2011 for Mac allows remote attackers to execute arbitrary code via crafted PNG data in an Office document, leading to impro…
- CVE-2009-2502CVSS 8.1 · High
Buffer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002…
- CVE-2026-71958CVSS 9.3 · Critical
D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the quicksetup.cgi interface. A remote attac…
- CVE-2026-71957CVSS 9.3 · Critical
D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the app.cgi interface. A remote attacker can…
- CVE-2026-20348CVSS 7.5 · High
A vulnerability in the XAR file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of&…
- CVE-2026-20337CVSS 7.5 · High
A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to…