Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2006-3431

EPSS 72.97% · P99
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2006-3431

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Buffer overflow in certain Asian language versions of Microsoft Excel might allow user-assisted attackers to execute arbitrary code via a crafted STYLE record in a spreadsheet that triggers the overflow when the user attempts to repair the document or selects the "Style" option, as demonstrated by nanika.xls. NOTE: Microsoft has confirmed to CVE via e-mail that this is different than the other Excel vulnerabilities announced before 20060707, including CVE-2006-3059 and CVE-2006-3086.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Microsoft Excel样式处理及修复远程代码执行漏洞(MS06-059)
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Microsoft Excel是非常流行的电子表格工具。 Excel在解析文件和处理畸形的STYLE记录时存在缓冲区溢出漏洞,攻击者可能利用此漏洞在用户机器上执行任意指令。如果用户使用管理用户权限登录,成功利用此漏洞的攻击者便可完全控制受影响的系统。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Shenlong Deep Dive — AI Deep Analysis

10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2006-3431

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2006-3431

登录查看更多情报信息。

Same Patch Batch · n/a · 2006-07-07 · 29 CVEs total

CVE-2006-3417Tor client is_fast或is_stable标记节点漏洞
CVE-2006-3430PatchLink Update 'Checkprofile.ASP' SQL注入漏洞
CVE-2006-3429TTCalc Script Loan And Mortgage 跨站脚本攻击(XSS) 漏洞
CVE-2006-3428TTCalc Script Loan And Mortgage跨站脚本攻击(XSS) 漏洞
CVE-2006-3427Microsoft IE StructuredGraphicsControl远程拒绝服务漏洞
CVE-2006-3426PatchLink Update Server目录遍历漏洞
CVE-2006-3425PatchLink Update Server 'Proxyreg.ASP'认证绕过漏洞
CVE-2006-3424WebEx Downloader ActiveX控件 多个缓冲区溢出漏洞
CVE-2006-3423WebEx Downloader插件GpcUrlRoot和GpcIniFileName ActiveX/Java控件远程代码执行漏洞
CVE-2006-3422WonderEdit Pro 'User_Bottom.PHP'远程文件包含漏洞
CVE-2006-3421SmartSiteCMS多个远程文件包含漏洞
CVE-2006-3420MyBulletinBoard 'editpost.php '跨站请求伪造(CSRF) 漏洞
CVE-2006-3419Tor before OpenSSL伪随机暴力破解漏洞
CVE-2006-3418Tor 验证服务器伪造权限漏洞
CVE-2006-3458Zope Docutils模块信息泄露漏洞
CVE-2006-3416Tor 中继命令网路解散漏洞
CVE-2006-3415Tor 未明中间人(MITM)攻击漏洞
CVE-2006-3414Tor before 非IP地址的服务器描述符漏洞
CVE-2006-3413Tor "logfile"记录敏感的信息信息泄露漏洞
CVE-2006-3412Tor before dir服务器、直接连接或代理服务器安全绕过漏洞

Showing top 20 of 29 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2006-3431

No comments yet


Leave a comment