CVE-2006-1245

Microsoft Internet Explorer 6.0.2900.2180 - Buffer Overflow

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2006-1245. PoCs published by Michal Zalewski.

AI-analyzed exploit summary This exploit leverages a buffer overflow vulnerability in MSHTML.DLL in Internet Explorer 6. The PoC uses a recursive string concatenation in JavaScript to trigger the overflow, potentially leading to a crash or remote code execution.

Description

Buffer overflow in mshtml.dll in Microsoft Internet Explorer 6.0.2900.2180, and probably other versions, allows remote attackers to execute arbitrary code via an HTML tag with a large number of script action handlers such as onload and onmouseover, as demonstrated using onclick, aka the "Multiple Event Handler Memory Corruption Vulnerability."

Exploits (2)

exploitdb WORKING POC VERIFIED
by Michal Zalewski · textdoswindows
https://www.exploit-db.com/exploits/27433

This exploit leverages a buffer overflow vulnerability in MSHTML.DLL in Internet Explorer 6. The PoC uses a recursive string concatenation in JavaScript to trigger the overflow, potentially leading to a crash or remote code execution.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Theoretical
Target: Microsoft Internet Explorer 6
No auth needed
Prerequisites: Victim must visit a malicious webpage using Internet Explorer 6
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC
htmldoswindows
https://www.exploit-db.com/exploits/1838

This is a proof-of-concept exploit for CVE-2006-1245, which targets a vulnerability in Internet Explorer. The exploit uses malformed HTML tags to trigger a memory corruption issue, potentially leading to remote code execution.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Microsoft Internet Explorer
No auth needed
Prerequisites: Victim must visit a malicious webpage using a vulnerable version of Internet Explorer
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (19)

Core 19
Core References
Patch vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1015794
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/453554/100/0/threaded
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/18957
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1569
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/19269
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1451
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/428810/100/0/threaded
Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA06-101A.html
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1632
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/25292
Exploit, Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/17131
Third Party Advisory mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2006-02/0855.html
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1599
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/453436/100/0/threaded
Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/984473
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1766
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/1318
Exploit vdb-entry x_refsource_osvdb
http://www.osvdb.org/23964

Scores

EPSS 0.6967
EPSS Percentile 98.7%

Details

Status published
Products (1)
microsoft/ie 6.0 sp2
Published Mar 17, 2006
Tracked Since Feb 18, 2026