Unspecified versions of Internet Explorer allow remote attackers to cause a denial of service (crash) via an IFRAME with a src tag containing a "File://" URI followed by an 8-bit character. NOTE: some third parties were unable to verify this issue.
Link | Tags |
---|---|
http://www.securityfocus.com/archive/1/436889/100/200/threaded | mailing list |
http://archives.neohapsis.com/archives/bugtraq/2006-06/0074.html | mailing list exploit |
http://www.securityfocus.com/archive/1/436839/100/200/threaded | mailing list |
http://securityreason.com/securityalert/1132 | third party advisory |