CVE-2006-1245
Buffer overflow in mshtml.dll in Microsoft Internet Explorer 6.0.2900.2180, and probably other versions, allows remote attackers to execute arbitrary code via an HTML tag with a large number of script action handlers such as onload and onmouseover, as…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 61.8%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
Buffer overflow in mshtml.dll in Microsoft Internet Explorer 6.0.2900.2180, and probably other versions, allows remote attackers to execute arbitrary code via an HTML tag with a large number of script action handlers such as onload and onmouseover, as demonstrated using onclick, aka the "Multiple Event Handler Memory Corruption Vulnerability."
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 61.82% probability · 99th percentile
- CISA KEV
- Not listed
- Affected
- microsoft/ie
- Source
- secure@microsoft.com
References
- http://archives.neohapsis.com/archives/bugtraq/2006-02/0855.html
- http://secunia.com/advisories/18957Patch, Vendor Advisory
- http://secunia.com/advisories/19269Patch, Vendor Advisory
- http://securitytracker.com/id?1015794Patch
- http://www.kb.cert.org/vuls/id/984473Third Party Advisory, US Government Resource
- http://www.osvdb.org/23964Exploit
- http://www.securityfocus.com/archive/1/428810/100/0/threaded
- http://www.securityfocus.com/archive/1/453436/100/0/threaded
- http://www.securityfocus.com/archive/1/453554/100/0/threaded
- http://www.securityfocus.com/bid/17131Exploit, Patch
- http://www.us-cert.gov/cas/techalerts/TA06-101A.htmlThird Party Advisory, US Government Resource
- http://www.vupen.com/english/advisories/2006/1318
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-013
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25292
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1451
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1569
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1599
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1632
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1766
- http://archives.neohapsis.com/archives/bugtraq/2006-02/0855.html
- http://secunia.com/advisories/18957Patch, Vendor Advisory
- http://secunia.com/advisories/19269Patch, Vendor Advisory
- http://securitytracker.com/id?1015794Patch
- http://www.kb.cert.org/vuls/id/984473Third Party Advisory, US Government Resource
- http://www.osvdb.org/23964Exploit
- http://www.securityfocus.com/archive/1/428810/100/0/threaded
- http://www.securityfocus.com/archive/1/453436/100/0/threaded
- http://www.securityfocus.com/archive/1/453554/100/0/threaded
- http://www.securityfocus.com/bid/17131Exploit, Patch
- http://www.us-cert.gov/cas/techalerts/TA06-101A.htmlThird Party Advisory, US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.