CVE-2006-7065
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
02/03/2007
Last modified:
09/04/2025
Description
Microsoft Internet Explorer allows remote attackers to cause a denial of service (crash) via an IFRAME with a certain XML file and XSL stylesheet that triggers a crash in mshtml.dll when a refresh is called, probably a null pointer dereference.
Impact
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:microsoft:ie:6:*:microsoft_windows_server_2003_sp1:*:*:*:*:* | ||
cpe:2.3:a:microsoft:ie:6:*:windows_2000:*:*:*:*:* | ||
cpe:2.3:a:microsoft:ie:6:*:windows_server_2003:*:*:*:*:* | ||
cpe:2.3:a:microsoft:ie:6:*:windows_xp_professional_64bit:*:*:*:*:* | ||
cpe:2.3:a:microsoft:ie:6:sp1:windows_98:*:*:*:*:* | ||
cpe:2.3:a:microsoft:ie:6:sp1:windows_98_se:*:*:*:*:* | ||
cpe:2.3:a:microsoft:ie:6:sp1:windows_millennium:*:*:*:*:* | ||
cpe:2.3:a:microsoft:ie:6:sp1:windows_xpsp1:*:*:*:*:* | ||
cpe:2.3:a:microsoft:ie:6:windows_2000_sp4:*:*:*:*:*:* | ||
cpe:2.3:a:microsoft:ie:6:windows_server_2003_sp1:*:*:*:*:*:* | ||
cpe:2.3:a:microsoft:ie:6:windows_server_2003_sp1_itanium:*:*:*:*:*:* | ||
cpe:2.3:a:microsoft:ie:6:windows_server_2003_sp1_itanium_systems:*:*:*:*:*:* | ||
cpe:2.3:a:microsoft:ie:6:windows_xp_sp2:*:*:*:*:*:* | ||
cpe:2.3:a:microsoft:ie:6.0:*:windows_server:*:*:*:*:* | ||
cpe:2.3:a:microsoft:ie:6.0:*:windows_server_2003:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://archives.neohapsis.com/archives/fulldisclosure/2006-08/0163.html
- http://www.securityfocus.com/bid/19364
- http://www3.ca.com/be/securityadvisor/vulninfo/Vuln.aspx?ID=34511
- http://archives.neohapsis.com/archives/fulldisclosure/2006-08/0163.html
- http://www.securityfocus.com/bid/19364
- http://www3.ca.com/be/securityadvisor/vulninfo/Vuln.aspx?ID=34511