CVE-2007-0811
Microsoft Internet Explorer 6.0 SP1 on Windows 2000, and 6.0 SP2 on Windows XP, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an HTML document containing a certain JavaScript for loop with an…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 18.1%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
Microsoft Internet Explorer 6.0 SP1 on Windows 2000, and 6.0 SP2 on Windows XP, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an HTML document containing a certain JavaScript for loop with an empty loop body, possibly involving getElementById.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
- EPSS
- 18.07% probability · 97th percentile
- CISA KEV
- Not listed
- Affected
- microsoft/ie
- Source
- cve@mitre.org
References
- http://osvdb.org/37636
- http://www.powerhacker.net/exploit/IE_NULL_CRASH.htmlExploit, URL Repurposed
- http://www.securityfocus.com/bid/22408
- https://www.exploit-db.com/exploits/3272
- http://osvdb.org/37636
- http://www.powerhacker.net/exploit/IE_NULL_CRASH.htmlExploit, URL Repurposed
- http://www.securityfocus.com/bid/22408
- https://www.exploit-db.com/exploits/3272
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.