Description
Microsoft Internet Explorer 6.0.2900.2180 and earlier allows remote attackers to cause a denial of service (CPU and memory consumption) via a long Unicode string argument to the write method, a related issue to CVE-2009-2479. NOTE: it was later reported that 7.0.6000.16473 and earlier are also affected.
References (6)
Core 6
Core References
Exploit x_refsource_misc
http://websecurity.com.ua/3338/
Third Party Advisory mailing-list
x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2009-07/0193.html
Third Party Advisory mailing-list
x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2009-07/0192.html
Third Party Advisory, VDB Entry mailing-list
x_refsource_bugtraq
http://www.securityfocus.com/archive/1/505120/100/0/threaded
Third Party Advisory, VDB Entry mailing-list
x_refsource_bugtraq
http://www.securityfocus.com/archive/1/505092/100/0/threaded
Third Party Advisory, VDB Entry mailing-list
x_refsource_bugtraq
http://www.securityfocus.com/archive/1/505122/100/0/threaded
Scores
EPSS
0.1488
EPSS Percentile
96.4%
Details
CWE
CWE-399
Status
published
Products (25)
microsoft/ie
(2 CPE variants)
microsoft/ie
2.0
microsoft/ie
2.0_beta
microsoft/ie
3.0 (2 CPE variants)
microsoft/ie
3.0.1
microsoft/ie
3.01
microsoft/ie
3.1
microsoft/ie
4.0 (5 CPE variants)
microsoft/ie
4.0.1 (4 CPE variants)
microsoft/ie
4.0a
... and 15 more
Published
Jul 22, 2009
Tracked Since
Feb 18, 2026