CVE-2006-3637

Microsoft Internet Explorer <6 - RCE

Title source: llm

Description

Microsoft Internet Explorer 5.01 SP4 and 6 does not properly handle various HTML layout component combinations, which allows user-assisted remote attackers to execute arbitrary code via a crafted HTML file that leads to memory corruption, aka "HTML Rendering Memory Corruption Vulnerability."

Exploits (1)

exploitdb WRITEUP VERIFIED
by Kil13r · textdoswindows
https://www.exploit-db.com/exploits/27971

Scores

EPSS 0.7725
EPSS Percentile 99.0%

Details

Status published
Products (2)
microsoft/ie 6 windows_server_2003_sp1
microsoft/internet_explorer 5.01 sp4
Published Aug 08, 2006
Tracked Since Feb 18, 2026