CVE-2006-1359

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
23/03/2006
Last modified:
03/04/2025

Description

Microsoft Internet Explorer 6 and 7 Beta 2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a certain createTextRange call on a checkbox object, which results in a dereference of an invalid table pointer.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:microsoft:ie:6.0:sp1:*:*:*:*:*:*
cpe:2.3:a:microsoft:ie:6.0:sp2:*:*:*:*:*:*
cpe:2.3:a:microsoft:ie:7.0:beta_2:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:6.0:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools