PT-2004-1598 · Microsoft · Internet Explorer
Berend-Jan Wever
+2
·
Published
2004-05-20
·
Updated
2016-10-18
·
CVE-2004-0479
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Internet Explorer version 6
Description
The issue allows remote attackers to cause a denial of service, resulting in a crash. This is achieved through the use of Javascript that creates a new popup window and disables the imagetoolbar functionality with a META tag, triggering a null dereference.
Recommendations
For Internet Explorer version 6, consider disabling Javascript execution in popup windows as a temporary workaround until a patch is available. Restrict the use of META tags that modify imagetoolbar functionality to minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Internet Explorer