Microsoft Internet Explorer 6 SP2 and earlier allows remote attackers to cause a denial of service (crash) via certain malformed HTML, possibly involving applet and base tags without required arguments, which triggers a null pointer dereference in mshtml.dll.
Link | Tags |
---|---|
http://www.securityfocus.com/archive/1/435095/30/4710/threaded | mailing list |
http://securityreason.com/securityalert/2286 | third party advisory |
http://www.securityfocus.com/bid/18112 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/26808 | vdb entry |
http://www.securityfocus.com/archive/1/435129/30/4710/threaded | mailing list |