CVE-2006-0585
jscript.dll in Microsoft Internet Explorer 6.0 SP1 and earlier allows remote attackers to cause a denial of service (application crash) via a Shockwave Flash object that contains ActionScript code that calls VBScript, which in turn calls the Javascript…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 15.2%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
jscript.dll in Microsoft Internet Explorer 6.0 SP1 and earlier allows remote attackers to cause a denial of service (application crash) via a Shockwave Flash object that contains ActionScript code that calls VBScript, which in turn calls the Javascript document.write function, which triggers a null dereference.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
- EPSS
- 15.24% probability · 97th percentile
- CISA KEV
- Not listed
- Affected
- microsoft/internet explorer
- Source
- cve@mitre.org
References
- http://securitytracker.com/id?1015559Exploit
- http://www.securityfocus.com/archive/1/423675/100/0/threaded
- http://www.securityfocus.com/archive/1/425422/30/6890/threaded
- http://www.securityfocus.com/bid/16441Exploit
- http://securitytracker.com/id?1015559Exploit
- http://www.securityfocus.com/archive/1/423675/100/0/threaded
- http://www.securityfocus.com/archive/1/425422/30/6890/threaded
- http://www.securityfocus.com/bid/16441Exploit
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.