PT-2009-2774 · Microsoft · Internet Explorer
Published
2009-01-08
·
Updated
2024-02-14
·
CVE-2009-0072
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Microsoft Internet Explorer versions 6.0 through 8.0 beta2
Description
The issue allows remote attackers to cause a denial of service, resulting in an application crash. This is achieved by using an
onload attribute with a specific value, screen[""], in a BODY element.Recommendations
For Microsoft Internet Explorer versions 6.0 through 8.0 beta2, consider avoiding the use of the
onload attribute in BODY elements until a fix is available. As a temporary workaround, restrict the execution of scripts within the BODY element to prevent potential crashes.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Internet Explorer