Lucene search

K
cve[email protected]CVE-2006-7066
HistoryMar 02, 2007 - 9:18 p.m.

CVE-2006-7066

2007-03-0221:18:00
web.nvd.nist.gov
24
2
cve-2006-7066
microsoft internet explorer
remote attackers
denial of service
crash
windows xp
nvd
security vulnerability
null pointer dereference

7.1 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:N/I:N/A:C

6.6 Medium

AI Score

Confidence

High

0.203 Low

EPSS

Percentile

96.4%

Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) by creating an object inside an iframe, deleting the frame by setting its location.href to about:blank, then accessing a property of the object within the deleted frame, which triggers a NULL pointer dereference. NOTE: it was later reported that 7.0.6000.16473 and earlier are also affected.

Affected configurations

NVD
Node
microsoftwindows_xpMatch-sp2
AND
microsoftinternet_explorerMatch6.0
OR
microsoftinternet_explorerMatch6.0sp1
OR
microsoftinternet_explorerMatch6.0sp2

Social References

More

7.1 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:N/I:N/A:C

6.6 Medium

AI Score

Confidence

High

0.203 Low

EPSS

Percentile

96.4%

Related for CVE-2006-7066