Microsoft Internet Explorer 5.0 through 6.0 allows remote attackers to cause a denial of service (crash) via an object of type "text/html" with the DATA field that identifies the HTML document that contains the object, which may cause infinite recursion.
Link | Tags |
---|---|
http://online.securityfocus.com/archive/1/268776 | mailing list |
http://www.securityfocus.com/bid/4564 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/8904 | vdb entry |