PT-2006-4385 · Microsoft · Internet Explorer 6+1

Published

2006-07-11

·

Updated

2017-07-20

·

CVE-2006-3510

CVSS v2.0

2.6

Low

VectorAV:N/AC:H/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Internet Explorer 6 on Windows 2000
Description The issue allows remote attackers to cause a denial of service (crash) via a series of operations that result in an invalid length calculation when using SysAllocStringLen, then triggers a buffer over-read.
Recommendations For Internet Explorer 6 on Windows 2000, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-3510

Affected Products

Internet Explorer 6
Windows 2000