PT-2009-2774 · Microsoft · Internet Explorer

Published

2009-01-08

·

Updated

2024-02-14

·

CVE-2009-0072

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Microsoft Internet Explorer versions 6.0 through 8.0 beta2
Description The issue allows remote attackers to cause a denial of service, resulting in an application crash. This is achieved by using an onload attribute with a specific value, screen[""], in a BODY element.
Recommendations For Microsoft Internet Explorer versions 6.0 through 8.0 beta2, consider avoiding the use of the onload attribute in BODY elements until a fix is available. As a temporary workaround, restrict the execution of scripts within the BODY element to prevent potential crashes.

Exploit

Fix

Related Identifiers

CVE-2009-0072

Affected Products

Internet Explorer