Skip to main content

CVE detail

CVE-2006-3086

Stack-based buffer overflow in the HrShellOpenWithMonikerDisplayName function in Microsoft Hyperlink Object Library (hlink.dll) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long hyperlink, as demonstrated using an Excel worksheet with a long link in Unicode, aka "Hyperlink COM Object Buffer Overflow Vulnerability." NOTE: this is a different issue than CVE-2006-3059.

CVSS 9.3 · CriticalBuzz score 11.9

Buzz score

Why this CVE is surfacing

Buzz score total 11.9

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 6.9 · diversity 5.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Mention score
6.9
1 evidence mentions in the snapshot
Diversity score
5.0
1 sources across 1 categories
KEV score
0.0
No KEV entry observed
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
1 source links · newest first
  • OfficeCat is a command line utility developed by the Sourcefire VRT that can be used to process Microsoft Office Documents to determine the presence of potential exploit conditions in the file. Officecat is available for Windows and Linux. Vulnerabilities checked by OfficeCat: CVE-2006-0001 CVE-2006-1301 CVE-2006-1306 CVE-2006-1308 CVE-2006-1540 CVE-2006-2492 CVE-2006-3014 CVE-2006-3086 CVE-2006-3431 CVE-2006-3432 CVE-2006-3493 CVE-2006-3590 CVE-2006-3656 CVE-2006-3864 CVE-2006-3865 CVE-2006-3875 CVE-2006-3876 CVE-2006-3877 CVE-2006-4534 CVE-2006-4694 CVE-2006-4700 CVE-2006-4701 CVE-2006-5994 CVE-2006-5995 CVE-2006-6456 CVE-2006-6561 CVE-2007-0027 CVE-2007-0030 CVE-2007-0031 CVE-2007-0515 CVE-2007-0671 CVE-2007-1203 CVE-2007-1214 … More →

    newswww.helpnetsecurity.comNov 2, 2009, 3:02 PM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence
  • CVE-2026-75090

    A vulnerability was detected in EricLBuehler Mistral.rs up to 0.8.22. Affected by this issue is the function convert_gguf_to_hf_tokenizer of the file mistralrs-core/src/gguf/gguf_…

    CVSS 2.1 · Low
    9 mentions
  • CVE-2026-74843

    A vulnerability was determined in Wavlink WN531P3 and WN535M1 V250922. Affected by this vulnerability is the function strcpy of the file /etc/lighttpd/www/cgi-bin/export_pingortra…

    CVSS 9.3 · Critical
    5 mentions
  • CVE-2026-19999

    A security vulnerability has been detected in Open Asset Import Library Assimp Assimp 17c12da. The affected element is the function Assimp::MDLImporter::ParseBoneTrafoKeys_3DGS_MD…

    CVSS 2.1 · Low
    8 mentions
  • CVE-2026-19970

    A vulnerability was detected in Open Asset Import Library Assimp 17c12da. This affects the function Assimp::MDLImporter::AddBonesToNodeGraph_3DGS_MDL7 of the file code/AssetLib/MD…

    CVSS 2.1 · Low
    6 mentions
  • CVE-2026-19969

    A security vulnerability has been detected in Open Asset Import Library Assimp 17c12da. The impacted element is the function Assimp::MDLImporter::GenerateOutputMeshes_3DGS_MDL7 of…

    CVSS 2.1 · Low
    6 mentions
  • CVE-2026-19968

    A weakness has been identified in Open Asset Import Library Assimp 17c12da. The affected element is the function Assimp::MDLImporter::ReadFaces_3DGS_MDL7 in the library code/Asset…

    CVSS 2.1 · Low
    8 mentions