CVE-2006-3510

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
11/07/2006
Last modified:
03/04/2025

Description

The Remote Data Service Object (RDS.DataControl) in Microsoft Internet Explorer 6 on Windows 2000 allows remote attackers to cause a denial of service (crash) via a series of operations that result in an invalid length calculation when using SysAllocStringLen, then triggers a buffer over-read.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:microsoft:ie:6.0:*:windows_server:*:*:*:*:*
cpe:2.3:a:microsoft:ie:6.0:sp1:windows_2000:*:*:*:*:*