CVE-2009-2655

Microsoft Internet Explorer <8 - DoS

Title source: llm

Description

mshtml.dll in Microsoft Internet Explorer 7 and 8 on Windows XP SP3 allows remote attackers to cause a denial of service (application crash) by calling the JavaScript findText method with a crafted Unicode string in the first argument, and only one additional argument, as demonstrated by a second argument of -1.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Hong10 · htmldoswindows
https://www.exploit-db.com/exploits/9253

Scores

EPSS 0.2260
EPSS Percentile 95.9%

Details

CWE
CWE-20
Status published
Products (2)
microsoft/internet_explorer 7
microsoft/internet_explorer 8
Published Aug 03, 2009
Tracked Since Feb 18, 2026