Vulnerability CVE-2006-1992


Published: 2006-04-24   Modified: 2012-02-12

Description:
mshtml.dll 6.00.2900.2873, as used in Microsoft Internet Explorer, allows remote attackers to cause a denial of service (crash) via nested OBJECT tags, which trigger invalid pointer dereferences including NULL dereferences. NOTE: the possibility of code execution was originally theorized, but Microsoft has stated that this issue is non-exploitable.

See advisories in our WLB2 database:
Topic
Author
Date
High
MSIE (mshtml.dll) OBJECT tag vulnerability
Michal Zalewski ...
26.04.2006

Type:

CWE-399

(Resource Management Errors)

CVSS2 => (AV:N/AC:H/Au:N/C:N/I:N/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
2.6/10
2.9/10
4.9/10
Exploit range
Attack complexity
Authentication
Remote
High
No required
Confidentiality impact
Integrity impact
Availability impact
None
None
Partial
Affected software
Microsoft -> IE 

 References:
http://archives.neohapsis.com/archives/fulldisclosure/2006-04/0616.html
http://lists.grok.org.uk/pipermail/full-disclosure/2006-April/045422.html
http://securityreason.com/securityalert/781
http://securitytracker.com/id?1016001
http://securitytracker.com/id?1016291
http://www.securityfocus.com/archive/1/431796/100/0/threaded
http://www.securityfocus.com/bid/17658
http://www.vupen.com/english/advisories/2006/1507
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-021
https://exchange.xforce.ibmcloud.com/vulnerabilities/25978

Copyright 2026, cxsecurity.com

 

Back to Top