CVE-2006-3637

Scores

EPSS

0.773medium77.3%
0%20%40%60%80%100%

Percentile: 77.3%

CVSS

5.1medium2.0
0246810

CVSS Score: 5.1/10

All CVSS Scores

CVSS 2.0
5.1

Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P

Description

Microsoft Internet Explorer 5.01 SP4 and 6 does not properly handle various HTML layout component combinations, which allows user-assisted remote attackers to execute arbitrary code via a crafted HTML file that leads to memory corruption, aka “HTML Rendering Memory Corruption Vulnerability.”

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

nvd

Exploits

Exploit ID: 27971

Source: exploitdb

URL: https://www.exploit-db.com/exploits/27971

Recommendations

Source: nvd

Apply an updateThis vulnerability is addressed in Microsoft Security Bulletin MS06-042.Note that this patch may cause problems for certain users. Per Microsoft Knowledgebase Article 923762:Consider the following scenario. You run Microsoft Internet Explorer 6 Service Pack 1 (SP1) on a computer that is running Microsoft Windows XP with Service Pack (SP1) or Microsoft Windows 2000 with Service Pack 4 (SP4). You install the Internet Explorer cumulative security update that is documented in Microsoft Knowledge Base article 918899. In this scenario, Internet Explorer unexpectedly exits when you view a Web site that uses the HTTP 1.1 protocol and compression. Disable Active ScriptingThis vulnerability can be mitigated by disabling Active Scripting, as specified in the “Securing Your Web Browser” document. Although this does not remove the vulnerability, it does block known attack vectors.

URL: http://www.kb.cert.org/vuls/id/340060

Vulnerable Software (2)

Type: Configuration

Vendor: microsoft

Product: ie

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:a:microsoft:ie:6:windows_server_2003_sp1:*:*:*:*:*:*",      "vulnerable": true    },    {      "cpe23uri": "cpe:2.3:a:microsoft:internet_explore...

Source: nvd

Type: Configuration

Vendor: microsoft

Product: internet_explorer

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:a:microsoft:ie:6:windows_server_2003_sp1:*:*:*:*:*:*",      "vulnerable": true    },    {      "cpe23uri": "cpe:2.3:a:microsoft:internet_explore...

Source: nvd