CVE-2006-3427 Information

Description

Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (crash) by declaring the sourceURL attribute on an uninitialized DirectAnimation.StructuredGraphicsControl ActiveX Object which triggers a null dereference.

Reference

http://browserfun.blogspot.com/2006/07/mobb-6-structuredgraphicscontrol.html http://www.osvdb.org/26839 http://www.securityfocus.com/bid/18855 http://www.vupen.com/english/advisories/2006/2687 https://exchange.xforce.ibmcloud.com/vulnerabilities/27565 ie-structuredgraphicscontrol-sourceurl-dos(27565)

Share on: