The Java Plug-in 1.4.2_03 and 1.4.2_04 controls, and the 1.4.2_03 and 1.4.2_04 <applet> redirector controls, allow remote attackers to cause a denial of service (Internet Explorer crash) by creating a COM object of the class associated with the control's CLSID, which is not intended for use within Internet Explorer.
Weaknesses in this category are typically introduced during the configuration of the software.
Link | Tags |
---|---|
http://www.securityfocus.com/archive/1/391803 | mailing list |