PT-2002-2436 · Microsoft · Internet Explorer

Published

2002-12-31

·

Updated

2021-07-23

·

CVE-2002-1714

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Microsoft Internet Explorer versions 5.0 through 6.0
Description The issue allows remote attackers to cause a denial of service, resulting in a crash. This is achieved by using an object of type "text/html" with the DATA field that identifies the HTML document containing the object, potentially leading to infinite recursion.
Recommendations For Microsoft Internet Explorer versions 5.0 through 6.0, consider disabling the rendering of "text/html" objects with the DATA field as a temporary workaround until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-1714

Affected Products

Internet Explorer