AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2006-4066

LOW · CVSS 2.6 EPSS 6.37%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2006-08-10 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2006-4066
Severity
LOW
CVSS
2.6
EPSS
6.37%
Microsoft Windows

Original NVD Description

The Graphical Device Interface Plus library (gdiplus.dll) in Microsoft Windows XP SP2 allows context-dependent attackers to cause a denial of service (application crash) via certain images that trigger a divide-by-zero error, as demonstrated by a (1) .ico file, (2) .png file that crashes MSN Messenger, and (3) .jpg file that crashes Internet Explorer. NOTE: another researcher has not been able to reproduce this issue.