CVE-2009-2954

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
24/08/2009
Last modified:
09/04/2025

Description

Microsoft Internet Explorer 6.0.2900.2180 and earlier allows remote attackers to cause a denial of service (CPU consumption and application hang) via JavaScript code with a long string value for the hash property (aka location.hash), a related issue to CVE-2008-5715.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:microsoft:internet_explorer:*:*:*:*:*:*:*:* 6.0.2900.2180 (including)
cpe:2.3:a:microsoft:internet_explorer:3.0:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:3.0.1:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:3.0.2:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:3.1:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:3.2:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:4.0:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:4.0.1:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:4.0.1:sp1:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:4.0.1:sp2:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:4.01:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:4.1:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:4.01:sp1:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:4.5:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:4.40.308:*:*:*:*:*:*:*