Microsoft Internet Explorer 6 SP2 and earlier allows remote attackers to cause a denial of service (crash) via certain malformed HTML, possibly involving applet and base tags without required arguments, which triggers a null pointer dereference in mshtml.dll.
2007-02-23T03:28:00.000
2025-04-09T00:30:58.490
Deferred
CVSSv2: 5.0 (MEDIUM)
AV:N/AC:L/Au:N/C:N/I:N/A:P
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | microsoft | windows_2000 | * | No |
Operating System | microsoft | windows_2003_server | sp2 | No |
Operating System | microsoft | windows_98 | * | No |
Operating System | microsoft | windows_me | * | No |
Operating System | microsoft | windows_nt | * | No |
Operating System | microsoft | windows_vista | * | No |
Operating System | microsoft | windows_xp | * | No |
Application | microsoft | ie | 6.0 | Yes |