PT-2004-3368 · Microsoft · Internet Explorer

Published

2004-12-31

·

Updated

2021-07-23

·

CVE-2004-2476

CVSS v2.0

2.6

Low

VectorAV:N/AC:H/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions: Microsoft Internet Explorer version 6.0
Description: The issue allows remote attackers to cause a denial of service, resulting in an infinite loop and crash. This is achieved by using an IFRAME with "?" as the file source.
Recommendations: For Microsoft Internet Explorer version 6.0, consider avoiding the use of IFRAME elements with "?" as the file source until a fix is available. As a temporary workaround, restrict the use of IFRAME elements to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-2476

Affected Products

Internet Explorer