CVE-2006-1992
mshtml.dll 6.00.2900.2873, as used in Microsoft Internet Explorer, allows remote attackers to cause a denial of service (crash) via nested OBJECT tags, which trigger invalid pointer dereferences including NULL dereferences.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 40.4%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
mshtml.dll 6.00.2900.2873, as used in Microsoft Internet Explorer, allows remote attackers to cause a denial of service (crash) via nested OBJECT tags, which trigger invalid pointer dereferences including NULL dereferences. NOTE: the possibility of code execution was originally theorized, but Microsoft has stated that this issue is non-exploitable.
- CVSS 2.0
- 2.6 LOWAV:N/AC:H/Au:N/C:N/I:N/A:P
- EPSS
- 40.43% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-399
- Affected
- microsoft/internet explorer
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/fulldisclosure/2006-04/0616.html
- http://lists.grok.org.uk/pipermail/full-disclosure/2006-April/045422.html
- http://secunia.com/advisories/19762Patch, Vendor Advisory
- http://securityreason.com/securityalert/781
- http://securitytracker.com/id?1016001Exploit
- http://securitytracker.com/id?1016291Patch
- http://www.osvdb.org/27475
- http://www.securityfocus.com/archive/1/431796/100/0/threaded
- http://www.securityfocus.com/bid/17658Exploit
- http://www.vupen.com/english/advisories/2006/1507Vendor Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-021
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25978
- http://archives.neohapsis.com/archives/fulldisclosure/2006-04/0616.html
- http://lists.grok.org.uk/pipermail/full-disclosure/2006-April/045422.html
- http://secunia.com/advisories/19762Patch, Vendor Advisory
- http://securityreason.com/securityalert/781
- http://securitytracker.com/id?1016001Exploit
- http://securitytracker.com/id?1016291Patch
- http://www.osvdb.org/27475
- http://www.securityfocus.com/archive/1/431796/100/0/threaded
- http://www.securityfocus.com/bid/17658Exploit
- http://www.vupen.com/english/advisories/2006/1507Vendor Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-021
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25978
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.