Unrated severityNVD Advisory· Published Aug 1, 2006· Updated Apr 16, 2026
CVE-2006-3961
CVE-2006-3961
Description
Buffer overflow in McSubMgr ActiveX control (mcsubmgr.dll) in McAfee Security Center 6.0.23 for Internet Security Suite 2006, Wireless Home Network Security, Personal Firewall Plus, VirusScan, Privacy Service, SpamKiller, AntiSpyware, and QuickClean allows remote user-assisted attackers to execute arbitrary commands via long string parameters, which are later used in vsprintf.
Affected products
25cpe:2.3:a:mcafee:antispyware:2005:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:mcafee:antispyware:2005:*:*:*:*:*:*:*
- cpe:2.3:a:mcafee:antispyware:2006:*:*:*:*:*:*:*
cpe:2.3:a:mcafee:internet_security_suite:2004:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:mcafee:internet_security_suite:2004:*:*:*:*:*:*:*
- cpe:2.3:a:mcafee:internet_security_suite:2005:*:*:*:*:*:*:*
- cpe:2.3:a:mcafee:internet_security_suite:2006:*:*:*:*:*:*:*
cpe:2.3:a:mcafee:personal_firewall_plus:2004:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:mcafee:personal_firewall_plus:2004:*:*:*:*:*:*:*
- cpe:2.3:a:mcafee:personal_firewall_plus:2005:*:*:*:*:*:*:*
- cpe:2.3:a:mcafee:personal_firewall_plus:2006:*:*:*:*:*:*:*
cpe:2.3:a:mcafee:privacy_service:2004:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:mcafee:privacy_service:2004:*:*:*:*:*:*:*
- cpe:2.3:a:mcafee:privacy_service:2005:*:*:*:*:*:*:*
- cpe:2.3:a:mcafee:privacy_service:2006:*:*:*:*:*:*:*
cpe:2.3:a:mcafee:quickclean:2004:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:mcafee:quickclean:2004:*:*:*:*:*:*:*
- cpe:2.3:a:mcafee:quickclean:2005:*:*:*:*:*:*:*
- cpe:2.3:a:mcafee:quickclean:2006:*:*:*:*:*:*:*
cpe:2.3:a:mcafee:security_center:4.3:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:mcafee:security_center:4.3:*:*:*:*:*:*:*
- cpe:2.3:a:mcafee:security_center:6.0:*:*:*:*:*:*:*
- cpe:2.3:a:mcafee:security_center:6.0.22:*:*:*:*:*:*:*
- cpe:2.3:a:mcafee:security_center:6.0.23:*:*:*:*:*:*:*
cpe:2.3:a:mcafee:spamkiller:5.0:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:mcafee:spamkiller:5.0:*:*:*:*:*:*:*
- cpe:2.3:a:mcafee:spamkiller:6.0:*:*:*:*:*:*:*
- cpe:2.3:a:mcafee:spamkiller:7.0:*:*:*:*:*:*:*
- cpe:2.3:a:mcafee:wireless_home_network_security:2006:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
10- secunia.com/advisories/21264nvdPatchVendor Advisory
- www.securityfocus.com/bid/19265nvdPatch
- www.vupen.com/english/advisories/2006/3096nvdVendor Advisory
- www.kb.cert.org/vuls/id/481212nvdUS Government Resource
- securitytracker.com/idnvd
- ts.mcafeehelp.com/faq3.aspnvd
- www.eeye.com/html/research/advisories/AD2006807.htmlnvd
- www.eeye.com/html/research/upcoming/20060719.htmlnvd
- www.osvdb.org/27698nvd
- www.securityfocus.com/archive/1/442495/100/100/threadednvd
News mentions
0No linked articles in our index yet.