CVE-2006-1992

Severity CVSS v4.0:
Pending analysis
Type:
CWE-399 Resource Management Errors
Publication date:
25/04/2006
Last modified:
23/07/2021

Description

mshtml.dll 6.00.2900.2873, as used in Microsoft Internet Explorer, allows remote attackers to cause a denial of service (crash) via nested OBJECT tags, which trigger invalid pointer dereferences including NULL dereferences. NOTE: the possibility of code execution was originally theorized, but Microsoft has stated that this issue is non-exploitable.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:microsoft:internet_explorer:6.0.2900:*:*:*:*:*:*:*