CVE-2006-3357
Heap-based buffer overflow in HTML Help ActiveX control (hhctrl.ocx) in Microsoft Internet Explorer 6.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code by repeatedly setting the Image field of…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 35.3%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
Heap-based buffer overflow in HTML Help ActiveX control (hhctrl.ocx) in Microsoft Internet Explorer 6.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code by repeatedly setting the Image field of an Internet.HHCtrl.1 object to certain values, possibly related to improper escaping and long strings.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 35.27% probability · 98th percentile
- CISA KEV
- Not listed
- Affected
- microsoft/internet explorer
- Source
- cve@mitre.org
References
- http://browserfun.blogspot.com/2006/07/mobb-2-internethhctrl-image-property.html
- http://secunia.com/advisories/20906Vendor Advisory
- http://securitytracker.com/id?1016434
- http://www.kb.cert.org/vuls/id/159220US Government Resource
- http://www.osvdb.org/26835
- http://www.securityfocus.com/archive/1/442733/100/0/threaded
- http://www.securityfocus.com/bid/18769Exploit
- http://www.tippingpoint.com/security/advisories/TSRT-06-08.html
- http://www.us-cert.gov/cas/techalerts/TA06-220A.htmlUS Government Resource
- http://www.vupen.com/english/advisories/2006/2634
- http://www.vupen.com/english/advisories/2006/2635
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-046
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27573
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13
- http://browserfun.blogspot.com/2006/07/mobb-2-internethhctrl-image-property.html
- http://secunia.com/advisories/20906Vendor Advisory
- http://securitytracker.com/id?1016434
- http://www.kb.cert.org/vuls/id/159220US Government Resource
- http://www.osvdb.org/26835
- http://www.securityfocus.com/archive/1/442733/100/0/threaded
- http://www.securityfocus.com/bid/18769Exploit
- http://www.tippingpoint.com/security/advisories/TSRT-06-08.html
- http://www.us-cert.gov/cas/techalerts/TA06-220A.htmlUS Government Resource
- http://www.vupen.com/english/advisories/2006/2634
- http://www.vupen.com/english/advisories/2006/2635
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-046
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27573
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.