CVE-2006-3357

Heap-based buffer overflow in HTML Help ActiveX control (hhctrl.ocx) in Microsoft Internet Explorer 6.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code by repeatedly setting the Image field of an Internet.HHCtrl.1 object to certain values, possibly related to improper escaping and long strings.
References
Link Resource
http://browserfun.blogspot.com/2006/07/mobb-2-internethhctrl-image-property.html
http://secunia.com/advisories/20906 Vendor Advisory
http://securitytracker.com/id?1016434
http://www.kb.cert.org/vuls/id/159220 US Government Resource
http://www.osvdb.org/26835
http://www.securityfocus.com/archive/1/442733/100/0/threaded
http://www.securityfocus.com/bid/18769 Exploit
http://www.tippingpoint.com/security/advisories/TSRT-06-08.html
http://www.us-cert.gov/cas/techalerts/TA06-220A.html US Government Resource
http://www.vupen.com/english/advisories/2006/2634
http://www.vupen.com/english/advisories/2006/2635
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-046
https://exchange.xforce.ibmcloud.com/vulnerabilities/27573
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13
http://browserfun.blogspot.com/2006/07/mobb-2-internethhctrl-image-property.html
http://secunia.com/advisories/20906 Vendor Advisory
http://securitytracker.com/id?1016434
http://www.kb.cert.org/vuls/id/159220 US Government Resource
http://www.osvdb.org/26835
http://www.securityfocus.com/archive/1/442733/100/0/threaded
http://www.securityfocus.com/bid/18769 Exploit
http://www.tippingpoint.com/security/advisories/TSRT-06-08.html
http://www.us-cert.gov/cas/techalerts/TA06-220A.html US Government Resource
http://www.vupen.com/english/advisories/2006/2634
http://www.vupen.com/english/advisories/2006/2635
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-046
https://exchange.xforce.ibmcloud.com/vulnerabilities/27573
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13
Configurations

Configuration 1 (hide)

cpe:2.3:a:microsoft:internet_explorer:6.0:*:*:*:*:*:*:*

History

21 Nov 2024, 00:13

Type Values Removed Values Added
References () http://browserfun.blogspot.com/2006/07/mobb-2-internethhctrl-image-property.html - () http://browserfun.blogspot.com/2006/07/mobb-2-internethhctrl-image-property.html -
References () http://secunia.com/advisories/20906 - Vendor Advisory () http://secunia.com/advisories/20906 - Vendor Advisory
References () http://securitytracker.com/id?1016434 - () http://securitytracker.com/id?1016434 -
References () http://www.kb.cert.org/vuls/id/159220 - US Government Resource () http://www.kb.cert.org/vuls/id/159220 - US Government Resource
References () http://www.osvdb.org/26835 - () http://www.osvdb.org/26835 -
References () http://www.securityfocus.com/archive/1/442733/100/0/threaded - () http://www.securityfocus.com/archive/1/442733/100/0/threaded -
References () http://www.securityfocus.com/bid/18769 - Exploit () http://www.securityfocus.com/bid/18769 - Exploit
References () http://www.tippingpoint.com/security/advisories/TSRT-06-08.html - () http://www.tippingpoint.com/security/advisories/TSRT-06-08.html -
References () http://www.us-cert.gov/cas/techalerts/TA06-220A.html - US Government Resource () http://www.us-cert.gov/cas/techalerts/TA06-220A.html - US Government Resource
References () http://www.vupen.com/english/advisories/2006/2634 - () http://www.vupen.com/english/advisories/2006/2634 -
References () http://www.vupen.com/english/advisories/2006/2635 - () http://www.vupen.com/english/advisories/2006/2635 -
References () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-046 - () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-046 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/27573 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/27573 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13 -

Information

Published : 2006-07-06 20:05

Updated : 2024-11-21 00:13


NVD link : CVE-2006-3357

Mitre link : CVE-2006-3357

CVE.ORG link : CVE-2006-3357


JSON object : View

Products Affected

microsoft

  • internet_explorer