CVE-2006-3200

Internet Explorer - Denial of Service via IFRAME File URI with 8-bit Character

Title source: llm
STIX 2.1

Description

Unspecified versions of Internet Explorer allow remote attackers to cause a denial of service (crash) via an IFRAME with a src tag containing a "File://" URI followed by an 8-bit character. NOTE: some third parties were unable to verify this issue.

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/436889/100/200/threaded
Exploit mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2006-06/0074.html
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/436839/100/200/threaded
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/1132

Scores

EPSS 0.1569
EPSS Percentile 96.5%

Details

Status published
Products (1)
microsoft/internet_explorer 6.0.2900
Published Jun 23, 2006
Tracked Since Feb 18, 2026