AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2006-5559

HIGH · CVSS 9.3 EPSS 41.90%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2006-10-27 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2006-5559
Severity
HIGH
CVSS
9.3
EPSS
41.90%
Microsoft

Original NVD Description

The Execute method in the ADODB.Connection 2.7 and 2.8 ActiveX control objects (ADODB.Connection.2.7 and ADODB.Connection.2.8) in the Microsoft Data Access Components (MDAC) 2.5 SP3, 2.7 SP1, 2.8, and 2.8 SP1 does not properly track freed memory when the second argument is a BSTR, which allows remote attackers to cause a denial of service (Internet Explorer crash) and possibly execute arbitrary code via certain strings in the second and third arguments.