Heap-based buffer overflow in Internet Explorer 6 allows remote attackers to execute arbitrary code via long (1) SRC or (2) NAME attributes in IFRAME, FRAME, and EMBED elements, as originally discovered using the mangleme utility, aka "the IFRAME vulnerability" or the "HTML Elements Vulnerability."
Link | Tags |
---|---|
http://www.kb.cert.org/vuls/id/842160 | third party advisory us government resource |
http://lists.grok.org.uk/pipermail/full-disclosure/2004-October/028009.html | mailing list |
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-040 | vendor advisory |
http://marc.info/?l=bugtraq&m=109942758911846&w=2 | mailing list |
http://www.securityfocus.com/bid/11515 | vdb entry |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1294 | vdb entry signature |
http://lists.grok.org.uk/pipermail/full-disclosure/2004-October/028035.html | mailing list |
http://www.us-cert.gov/cas/techalerts/TA04-315A.html | third party advisory us government resource |
https://exchange.xforce.ibmcloud.com/vulnerabilities/17889 | vdb entry |
http://secunia.com/advisories/12959/ | third party advisory |
http://www.securityfocus.com/archive/1/379261 | mailing list |
http://www.us-cert.gov/cas/techalerts/TA04-336A.html | third party advisory us government resource |