CVE-2004-2011: Low severity microsoft internet explorer vulnerability
Published Dec 31, 2004
·Updated
msxml3.dll in Internet Explorer 6.0.2600.0 allows remote attackers to cause a denial of service (crash) via a single & (ampersand) in a <Ref href> link, which triggers a parsing error, possibly due to missing portions of the URI.
Affected Software
1 affected component
Microsoft Internet Explorer=6.0.2600
Event History
Dec 31, 2004
CVE Published
05:00 AM
May 10, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-2011?
CVE-2004-2011 is considered a denial of service vulnerability.
2
How do I fix CVE-2004-2011?
The best way to resolve CVE-2004-2011 is to upgrade to a newer version of Internet Explorer or apply any available security patches.
3
What software is affected by CVE-2004-2011?
CVE-2004-2011 affects Internet Explorer version 6.0.2600.
4
What type of attack does CVE-2004-2011 enable?
CVE-2004-2011 allows remote attackers to crash Internet Explorer using a malformed <Ref href> link.
5
When was CVE-2004-2011 disclosed?
CVE-2004-2011 was publicly disclosed in 2004.