Unrated severityNVD Advisory· Published Oct 16, 2006· Updated Apr 23, 2026
CVE-2006-5296
CVE-2006-5296
Description
PowerPoint in Microsoft Office 2003 does not properly handle a container object whose position value exceeds the record length, which allows user-assisted attackers to cause a denial of service (NULL dereference and application crash) via a crafted PowerPoint (.PPT) file, as demonstrated by Nanika.ppt, and a different vulnerability than CVE-2006-3435, CVE-2006-3876, CVE-2006-3877, and CVE-2006-4694. NOTE: the impact of this issue was originally claimed to be arbitrary code execution, but later analysis demonstrated that this was erroneous.
Affected products
1- cpe:2.3:a:microsoft:powerpoint:2003:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
11- www.securityfocus.com/bid/20495nvdExploit
- secunia.com/advisories/22394nvdVendor Advisory
- blogs.technet.com/msrc/archive/2006/10/12/poc-published-for-ms-office-2003-powerpoint.aspxnvd
- blogs.technet.com/msrc/archive/2006/11/10/follow-up-information-on-weblog-posting-about-poc-published-for-ms-office-2003-powerpoint.aspxnvd
- research.eeye.com/html/alerts/zeroday/20061012_2.htmlnvd
- securitytracker.com/idnvd
- www.informationweek.com/management/showArticle.jhtmlnvd
- www.osvdb.org/29720nvd
- www.vupen.com/english/advisories/2006/4031nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/29507nvd
- www.exploit-db.com/exploits/2523nvd
News mentions
0No linked articles in our index yet.