PT-2004-2036 · Microsoft · Internet Explorer 6

Published

2004-11-18

·

Updated

2021-07-23

·

CVE-2004-1050

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Internet Explorer 6
Description: A heap-based buffer overflow issue allows remote attackers to execute arbitrary code via long SRC or NAME attributes in IFRAME, FRAME, and EMBED elements.
Recommendations: For Internet Explorer 6, update to a newer version to mitigate the risk of exploitation. As a temporary workaround, consider restricting the use of IFRAME, FRAME, and EMBED elements until a patch is available. Avoid using long SRC or NAME attributes in these elements to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-1050

Affected Products

Internet Explorer 6