CVE-2006-3638
Status: ModifiedHigh (7.5)—
Microsoft Internet Explorer 5.01 and 6 does not properly handle uninitialized COM objects, which allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code, as demonstrated by the Nth function in the DirectAnimation.DATuple ActiveX control, aka "COM Object Instantiation Memory Corruption Vulnerability."
CVSS
- Version: 2.0
- Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P
- Base score: 7.5
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 37%
- Percentile among all scored CVEs: 98
- Score date: 10/9/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (2)
CWEs
- CWE-119
References
- http://secunia.com/advisories/21396
- http://securitytracker.com/id?1016663
- http://www.kb.cert.org/vuls/id/959049
- http://www.osvdb.org/27852
- http://www.securityfocus.com/archive/1/442728/100/0/threaded
- http://www.securityfocus.com/bid/19340
- http://www.tippingpoint.com/security/advisories/TSRT-06-09.html
- http://www.us-cert.gov/cas/techalerts/TA06-220A.html
- http://www.vupen.com/english/advisories/2006/3212
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-042
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A719
- http://secunia.com/advisories/21396
- http://securitytracker.com/id?1016663
- http://www.kb.cert.org/vuls/id/959049
- http://www.osvdb.org/27852
- http://www.securityfocus.com/archive/1/442728/100/0/threaded
- http://www.securityfocus.com/bid/19340
- http://www.tippingpoint.com/security/advisories/TSRT-06-09.html
- http://www.us-cert.gov/cas/techalerts/TA06-220A.html
- http://www.vupen.com/english/advisories/2006/3212
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-042
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A719
Raw JSON (NVD)
Show
{
"id": "CVE-2006-3638",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": true,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "secure@microsoft.com",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2006-08-08T23:04:00.000",
"references": [
{
"url": "http://secunia.com/advisories/21396",
"tags": [
"Vendor Advisory"
],
"source": "secure@microsoft.com"
},
{
"url": "http://securitytracker.com/id?1016663",
"source": "secure@microsoft.com"
},
{
"url": "http://www.kb.cert.org/vuls/id/959049",
"tags": [
"US Government Resource"
],
"source": "secure@microsoft.com"
},
{
"url": "http://www.osvdb.org/27852",
"source": "secure@microsoft.com"
},
{
"url": "http://www.securityfocus.com/archive/1/442728/100/0/threaded",
"source": "secure@microsoft.com"
},
{
"url": "http://www.securityfocus.com/bid/19340",
"source": "secure@microsoft.com"
},
{
"url": "http://www.tippingpoint.com/security/advisories/TSRT-06-09.html",
"source": "secure@microsoft.com"
},
{
"url": "http://www.us-cert.gov/cas/techalerts/TA06-220A.html",
"tags": [
"US Government Resource"
],
"source": "secure@microsoft.com"
},
{
"url": "http://www.vupen.com/english/advisories/2006/3212",
"tags": [
"Vendor Advisory"
],
"source": "secure@microsoft.com"
},
{
"url": "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-042",
"source": "secure@microsoft.com"
},
{
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A719",
"source": "secure@microsoft.com"
},
{
"url": "http://secunia.com/advisories/21396",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://securitytracker.com/id?1016663",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.kb.cert.org/vuls/id/959049",
"tags": [
"US Government Resource"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.osvdb.org/27852",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/442728/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/19340",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.tippingpoint.com/security/advisories/TSRT-06-09.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.us-cert.gov/cas/techalerts/TA06-220A.html",
"tags": [
"US Government Resource"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2006/3212",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-042",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A719",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-119"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Microsoft Internet Explorer 5.01 and 6 does not properly handle uninitialized COM objects, which allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code, as demonstrated by the Nth function in the DirectAnimation.DATuple ActiveX control, aka \"COM Object Instantiation Memory Corruption Vulnerability.\""
},
{
"lang": "es",
"value": "Microsoft Internet Explorer 5.01 y 6 no maneja adecuadamente objetos COM no inicializados, lo cual permite a atacantes remotos provocar una denegación de servicio (corrupción de memoria) y posiblemente ejecutar código de su elección, como ha sido demostrado por la función Nth en el control ActiveX DirectAnimation.DATuple, también conocido como \"Vulnerabilidad de Corrupción de Memoria en la Instanciación de Objetos COM\"."
}
],
"lastModified": "2026-06-16T22:27:28.543",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:microsoft:ie:6.0:sp1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "24DF2AB3-DEAB-4D70-986E-FFBB7E64B96A"
},
{
"criteria": "cpe:2.3:a:microsoft:ie:6.0:sp2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DA3D2175-7DF7-4D57-8B26-5BA68EF7A935"
},
{
"criteria": "cpe:2.3:a:microsoft:internet_explorer:5.0.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3A04FEA6-37B0-44B0-844F-55652ABA1F85"
},
{
"criteria": "cpe:2.3:a:microsoft:internet_explorer:5.0.1:sp1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4D56FB8E-2553-47C1-82A2-9E59023780CE"
},
{
"criteria": "cpe:2.3:a:microsoft:internet_explorer:5.0.1:sp2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8541EEED-94F4-42F8-9719-57F3EC85D52B"
},
{
"criteria": "cpe:2.3:a:microsoft:internet_explorer:5.0.1:sp3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "40372520-08CF-4F64-A7AC-7E0AE0964138"
},
{
"criteria": "cpe:2.3:a:microsoft:internet_explorer:5.0.1:sp4:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2EB39B99-91A0-4B70-B12A-BA37F6AFBA83"
},
{
"criteria": "cpe:2.3:a:microsoft:internet_explorer:6.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A19F6133-25D1-44A5-B6B9-354703436783"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "secure@microsoft.com"
}