CVE-2004-2434

Microsoft Internet Explorer 6.0 SP1 - DoS

Title source: llm

Description

Microsoft Internet Explorer 6.0 SP1 allows remote attackers to cause a denial of service (browser crash) via a link with "::{" (colon colon left brace), which triggers a null dereference when the user attempts to save the link using "Save As" and Internet Explorer prepares an error message with an attacker-controlled format string.

Exploits (1)

exploitdb WORKING POC VERIFIED
by anonymous · htmldoswindows
https://www.exploit-db.com/exploits/376

Scores

EPSS 0.0862
EPSS Percentile 92.3%

Classification

Status draft

Affected Products (1)

microsoft/ie

Timeline

Published Dec 31, 2004
Tracked Since Feb 18, 2026