CVE-2006-3451
Microsoft Internet Explorer 5 SP4 and 6 do not properly garbage collect when "multiple imports are used on a styleSheets collection" to construct a chain of Cascading Style Sheets (CSS), which allows remote attackers to execute arbitrary code via…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 41.2%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
Microsoft Internet Explorer 5 SP4 and 6 do not properly garbage collect when "multiple imports are used on a styleSheets collection" to construct a chain of Cascading Style Sheets (CSS), which allows remote attackers to execute arbitrary code via unspecified vectors.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 41.22% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- microsoft/ie
- Source
- secure@microsoft.com
References
- http://secunia.com/advisories/21396Vendor Advisory
- http://securityreason.com/securityalert/1343
- http://securitytracker.com/id?1016663
- http://www.kb.cert.org/vuls/id/262004Patch, US Government Resource
- http://www.osvdb.org/27854
- http://www.securityfocus.com/archive/1/442578/100/0/threaded
- http://www.securityfocus.com/bid/19316
- http://www.us-cert.gov/cas/techalerts/TA06-220A.htmlPatch, US Government Resource
- http://www.vupen.com/english/advisories/2006/3212Vendor Advisory
- http://www.zerodayinitiative.com/advisories/ZDI-06-026.html
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-042
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5
- http://secunia.com/advisories/21396Vendor Advisory
- http://securityreason.com/securityalert/1343
- http://securitytracker.com/id?1016663
- http://www.kb.cert.org/vuls/id/262004Patch, US Government Resource
- http://www.osvdb.org/27854
- http://www.securityfocus.com/archive/1/442578/100/0/threaded
- http://www.securityfocus.com/bid/19316
- http://www.us-cert.gov/cas/techalerts/TA06-220A.htmlPatch, US Government Resource
- http://www.vupen.com/english/advisories/2006/3212Vendor Advisory
- http://www.zerodayinitiative.com/advisories/ZDI-06-026.html
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-042
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.