PT-2009-2774 · Microsoft · Internet Explorer

CVE-2009-0072

·

Published

2009-01-08

·

Updated

2024-02-14

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Microsoft Internet Explorer versions 6.0 through 8.0 beta2
Description The issue allows remote attackers to cause a denial of service, resulting in an application crash. This is achieved by using an onload attribute with a specific value, screen[""], in a BODY element.
Recommendations For Microsoft Internet Explorer versions 6.0 through 8.0 beta2, consider avoiding the use of the onload attribute in BODY elements until a fix is available. As a temporary workaround, restrict the execution of scripts within the BODY element to prevent potential crashes.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2009-0072

Affected Products

Internet Explorer