[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2006-2383Date: (C)2006-06-13   (M)2023-12-22


Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allows remote attackers to execute arbitrary code via "unexpected data" related to "parameter validation" in the DXImageTransform.Microsoft.Light ActiveX control, which causes Internet Explorer to crash in a way that enables the code execution.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 9.3
Exploit Score: 8.6
Impact Score: 10.0
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: COMPLETE
Integrity: COMPLETE
Availability: COMPLETE
  
Reference:
SECTRACK-1016291
BID-18303
SECUNIA-20595
OSVDB-26444
ADV-2006-2319
MS06-021
TA06-164A
VU#417585
ie-dximagetransform-execute-code(26768)
oval:org.mitre.oval:def:1821
oval:org.mitre.oval:def:1891
oval:org.mitre.oval:def:1924
oval:org.mitre.oval:def:1944
oval:org.mitre.oval:def:1949
oval:org.mitre.oval:def:2009

CPE    2
cpe:/a:microsoft:internet_explorer:5.01:sp4
cpe:/a:microsoft:internet_explorer:6:sp1
OVAL    6
oval:org.mitre.oval:def:1924
oval:org.mitre.oval:def:1944
oval:org.mitre.oval:def:1891
oval:org.mitre.oval:def:1949
...

© SecPod Technologies