PT-2006-4594 · Microsoft · Internet Explorer 6+2

Published

2006-07-19

·

Updated

2021-12-13

·

CVE-2006-3729

CVSS v2.0

2.6

Low

VectorAV:N/AC:H/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Internet Explorer 6 on Windows XP SP2 with Office installed
Description The issue allows remote attackers to cause a denial of service (crash) via a large negative integer argument to the getDataMemberName method of a OWC11.DataSourceControl.11 object. This leads to an integer overflow and a null dereference.
Recommendations For Internet Explorer 6 on Windows XP SP2 with Office installed, consider avoiding the use of the getDataMemberName method with large negative integer arguments until a fix is available. As a temporary workaround, restrict the input to the getDataMemberName method to prevent large negative integers from being passed.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-3729

Affected Products

Internet Explorer 6
Office
Windows Xp