CVE-2006-5967
Estado: ModificadaMedia (5.1)—
Race condition in Panda ActiveScan 5.53.00, and other versions before 5.54.01, allows remote attackers to cause memory corruption and execute arbitrary code via unknown vectors related to multiple invocations of the Analizar method in the ActiveScan.1 ActiveX control, which is not thread safe.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P
- Puntuación base: 5.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 2.44%
- Percentil entre todas las CVEs puntuadas: 84
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- NVD-CWE-Other
Referencias
- http://secunia.com/advisories/21763
- http://secunia.com/secunia_research/2006-64/advisory/
- http://www.securityfocus.com/archive/1/451864/100/0/threaded
- http://www.securityfocus.com/bid/21132
- http://www.vupen.com/english/advisories/2006/4536
- https://exchange.xforce.ibmcloud.com/vulnerabilities/30319
- http://secunia.com/advisories/21763
- http://secunia.com/secunia_research/2006-64/advisory/
- http://www.securityfocus.com/archive/1/451864/100/0/threaded
- http://www.securityfocus.com/bid/21132
- http://www.vupen.com/english/advisories/2006/4536
- https://exchange.xforce.ibmcloud.com/vulnerabilities/30319
JSON original (NVD)
Mostrar
{
"id": "CVE-2006-5967",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5.1,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:H/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "HIGH",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 4.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": true,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "PSIRT-CNA@flexerasoftware.com",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2006-11-17T22:07:00.000",
"references": [
{
"url": "http://secunia.com/advisories/21763",
"source": "PSIRT-CNA@flexerasoftware.com"
},
{
"url": "http://secunia.com/secunia_research/2006-64/advisory/",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "PSIRT-CNA@flexerasoftware.com"
},
{
"url": "http://www.securityfocus.com/archive/1/451864/100/0/threaded",
"source": "PSIRT-CNA@flexerasoftware.com"
},
{
"url": "http://www.securityfocus.com/bid/21132",
"source": "PSIRT-CNA@flexerasoftware.com"
},
{
"url": "http://www.vupen.com/english/advisories/2006/4536",
"source": "PSIRT-CNA@flexerasoftware.com"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/30319",
"source": "PSIRT-CNA@flexerasoftware.com"
},
{
"url": "http://secunia.com/advisories/21763",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/secunia_research/2006-64/advisory/",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/451864/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/21132",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2006/4536",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/30319",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Race condition in Panda ActiveScan 5.53.00, and other versions before 5.54.01, allows remote attackers to cause memory corruption and execute arbitrary code via unknown vectors related to multiple invocations of the Analizar method in the ActiveScan.1 ActiveX control, which is not thread safe."
},
{
"lang": "es",
"value": "Condición de carrera en Panda ActiveScan 5.53.00, y otras versiones anteriores a 5.54.01, permiten a un atacante remoto provocar corrupción de memoria y ejecutar código de su elección a través de vectores desconocidos relacionados con múltiples invocaciones del método Analizar en el controlador ActiveX de ActiveScan.1, el cual no es un hilo seguro."
}
],
"lastModified": "2026-06-16T22:32:13.557",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:panda:activescan:5.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5AE78593-0DC5-47C1-9624-5E304A7215B9"
},
{
"criteria": "cpe:2.3:a:panda:activescan:5.53.00:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AA17277C-337F-4AE0-B92B-C572EEFCAF83"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "PSIRT-CNA@flexerasoftware.com",
"evaluatorSolution": "This vulnerability is addressed in the following product release:\r\nPanda, ActiveScan, 5.54.01"
}