CVE-2006-2723

Firefox - Denial of Service via Nested Marquee Tags

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2006-2723. PoCs published by n00b.

AI-analyzed exploit summary This exploit leverages a Denial of Service (DoS) vulnerability in Internet Explorer by using nested marquee tags to crash the browser. The excessive nesting causes a stack overflow, leading to a crash.

Description

Unspecified versions of Mozilla Firefox allow remote attackers to cause a denial of service (crash) via a web page that contains a large number of nested marquee tags. NOTE: a followup post indicated that the initial report could not be verified.

Exploits (1)

exploitdb WORKING POC VERIFIED
by n00b · htmldosmultiple
https://www.exploit-db.com/exploits/1867

This exploit leverages a Denial of Service (DoS) vulnerability in Internet Explorer by using nested marquee tags to crash the browser. The excessive nesting causes a stack overflow, leading to a crash.

Classification
Working Poc 90%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: Microsoft Internet Explorer (versions prior to patch for CVE-2006-2723)
No auth needed
Prerequisites: Victim must open the malicious HTML file in a vulnerable version of Internet Explorer
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/435411/100/0/threaded
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/436268/100/0/threaded
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/18165
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/435373/100/0/threaded
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/435882/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/26898

Scores

EPSS 0.0294
EPSS Percentile 85.3%

Details

Status published
Products (1)
mozilla/firefox 2.0 rc3
Published Jun 01, 2006
Tracked Since Feb 18, 2026