VYPR
Unrated severityNVD Advisory· Published Dec 10, 2006· Updated Apr 23, 2026

CVE-2006-6442

CVE-2006-6442

Description

Stack-based buffer overflow in the SetClientInfo function in the CDDBControlAOL.CDDBAOLControl ActiveX control (cddbcontrol.dll), as used in America Online (AOL) 7.0 4114.563, 8.0 4129.230, and 9.0 Security Edition 4156.910, and possibly other products, allows remote attackers to execute arbitrary code via a long ClientId argument.

Affected products

3
  • cpe:2.3:a:aol:aol_client_software:7.0_4114.563:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:aol:aol_client_software:7.0_4114.563:*:*:*:*:*:*:*
    • cpe:2.3:a:aol:aol_client_software:8.0_4129.230:*:*:*:*:*:*:*
    • cpe:2.3:a:aol:aol_client_software:9.0:*:security_4156.910:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

9

News mentions

0

No linked articles in our index yet.